• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

mendersoftware / mender-server / 1648430096

30 Jan 2025 12:04PM UTC coverage: 76.631% (+0.03%) from 76.597%
1648430096

Pull #394

gitlab-ci

bahaa-ghazal
fix: Limiting the size of metadata when uploading and generate artifacts

Changelog: Title
Ticket: MEN-7166
Signed-off-by: Bahaa Aldeen Ghazal <bahaa.ghazal@northern.tech>
Pull Request #394: fix: Limiting the size of metadata when uploading and generating artifacts

4328 of 6288 branches covered (68.83%)

Branch coverage included in aggregate %.

24 of 30 new or added lines in 1 file covered. (80.0%)

2 existing lines in 1 file now uncovered.

45446 of 58665 relevant lines covered (77.47%)

20.08 hits per line

Source File
Press 'n' to go to next uncovered line, 'b' for previous

79.71
/backend/services/deployments/api/http/api_deployments.go
1
// Copyright 2024 Northern.tech AS
2
//
3
//        Licensed under the Apache License, Version 2.0 (the "License");
4
//        you may not use this file except in compliance with the License.
5
//        You may obtain a copy of the License at
6
//
7
//            http://www.apache.org/licenses/LICENSE-2.0
8
//
9
//        Unless required by applicable law or agreed to in writing, software
10
//        distributed under the License is distributed on an "AS IS" BASIS,
11
//        WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12
//        See the License for the specific language governing permissions and
13
//        limitations under the License.
14

15
package http
16

17
import (
18
        "context"
19
        "encoding/json"
20
        "fmt"
21
        "io"
22
        "mime/multipart"
23
        "net/http"
24
        "net/url"
25
        "strconv"
26
        "strings"
27
        "time"
28

29
        "github.com/ant0ine/go-json-rest/rest"
30
        "github.com/asaskevich/govalidator"
31
        "github.com/pkg/errors"
32

33
        "github.com/mendersoftware/mender-server/pkg/config"
34
        "github.com/mendersoftware/mender-server/pkg/identity"
35
        "github.com/mendersoftware/mender-server/pkg/log"
36
        "github.com/mendersoftware/mender-server/pkg/requestid"
37
        "github.com/mendersoftware/mender-server/pkg/requestlog"
38
        "github.com/mendersoftware/mender-server/pkg/rest_utils"
39

40
        "github.com/mendersoftware/mender-server/services/deployments/app"
41
        dconfig "github.com/mendersoftware/mender-server/services/deployments/config"
42
        "github.com/mendersoftware/mender-server/services/deployments/model"
43
        "github.com/mendersoftware/mender-server/services/deployments/store"
44
        "github.com/mendersoftware/mender-server/services/deployments/utils"
45
)
46

47
func init() {
3✔
48
        rest.ErrorFieldName = "error"
3✔
49
}
3✔
50

51
const (
52
        // 15 minutes
53
        DefaultDownloadLinkExpire = 15 * time.Minute
54
        // 10 Mb
55
        MaxFormParamSize           = 1024 * 1024             // 1MiB
56
        DefaultMaxImageSize        = 10 * 1024 * 1024 * 1024 // 10GiB
57
        DefaultMaxGenerateDataSize = 512 * 1024 * 1024       // 512MiB
58

59
        // Pagination
60
        DefaultPerPage                      = 20
61
        MaximumPerPage                      = 500
62
        MaximumPerPageListDeviceDeployments = 20
63
)
64

65
const (
66
        // Header Constants
67
        hdrTotalCount    = "X-Total-Count"
68
        hdrLink          = "Link"
69
        hdrForwardedHost = "X-Forwarded-Host"
70
)
71

72
// storage keys
73
const (
74
        // Common HTTP form parameters
75
        ParamArtifactName = "artifact_name"
76
        ParamDeviceType   = "device_type"
77
        ParamUpdateType   = "update_type"
78
        ParamDeploymentID = "deployment_id"
79
        ParamDeviceID     = "device_id"
80
        ParamTenantID     = "tenant_id"
81
        ParamName         = "name"
82
        ParamTag          = "tag"
83
        ParamDescription  = "description"
84
        ParamPage         = "page"
85
        ParamPerPage      = "per_page"
86
        ParamSort         = "sort"
87
        ParamID           = "id"
88
)
89

90
const Redacted = "REDACTED"
91

92
// JWT token
93
const (
94
        HTTPHeaderAuthorization       = "Authorization"
95
        HTTPHeaderAuthorizationBearer = "Bearer"
96
)
97

98
const (
99
        defaultTimeout = time.Second * 10
100
)
101

102
// Errors
103
var (
104
        ErrIDNotUUID                      = errors.New("ID is not a valid UUID")
105
        ErrEmptyID                        = errors.New("id: cannot be blank")
106
        ErrArtifactUsedInActiveDeployment = errors.New("Artifact is used in active deployment")
107
        ErrInvalidExpireParam             = errors.New("Invalid expire parameter")
108
        ErrArtifactNameMissing            = errors.New(
109
                "request does not contain the name of the artifact",
110
        )
111
        ErrArtifactTypeMissing = errors.New(
112
                "request does not contain the type of artifact",
113
        )
114
        ErrArtifactDeviceTypesCompatibleMissing = errors.New(
115
                "request does not contain the list of compatible device types",
116
        )
117
        ErrArtifactFileMissing       = errors.New("request does not contain the artifact file")
118
        ErrModelArtifactFileTooLarge = errors.New("Artifact file too large")
119

120
        ErrInternal                   = errors.New("Internal error")
121
        ErrDeploymentAlreadyFinished  = errors.New("Deployment already finished")
122
        ErrUnexpectedDeploymentStatus = errors.New("Unexpected deployment status")
123
        ErrMissingIdentity            = errors.New("Missing identity data")
124
        ErrMissingSize                = errors.New("missing size form-data")
125
        ErrMissingGroupName           = errors.New("Missing group name")
126

127
        ErrInvalidSortDirection = fmt.Errorf("invalid form value: must be one of \"%s\" or \"%s\"",
128
                model.SortDirectionAscending, model.SortDirectionDescending)
129
)
130

131
type Config struct {
132
        // URL signing parameters:
133

134
        // PresignSecret holds the secret value used by the signature algorithm.
135
        PresignSecret []byte
136
        // PresignExpire duration until the link expires.
137
        PresignExpire time.Duration
138
        // PresignHostname is the signed url hostname.
139
        PresignHostname string
140
        // PresignScheme is the URL scheme used for generating signed URLs.
141
        PresignScheme string
142
        // MaxImageSize is the maximum image size
143
        MaxImageSize        int64
144
        MaxGenerateDataSize int64
145

146
        EnableDirectUpload bool
147
        // EnableDirectUploadSkipVerify allows turning off the verification of uploaded artifacts
148
        EnableDirectUploadSkipVerify bool
149

150
        // DisableNewReleasesFeature is a flag that turns off the new API end-points
151
        // related to releases; helpful in performing long-running maintenance and data
152
        // migrations on the artifacts and releases collections.
153
        DisableNewReleasesFeature bool
154
}
155

156
func NewConfig() *Config {
3✔
157
        return &Config{
3✔
158
                PresignExpire:       DefaultDownloadLinkExpire,
3✔
159
                PresignScheme:       "https",
3✔
160
                MaxImageSize:        DefaultMaxImageSize,
3✔
161
                MaxGenerateDataSize: DefaultMaxGenerateDataSize,
3✔
162
        }
3✔
163
}
3✔
164

165
func (conf *Config) SetPresignSecret(key []byte) *Config {
3✔
166
        conf.PresignSecret = key
3✔
167
        return conf
3✔
168
}
3✔
169

170
func (conf *Config) SetPresignExpire(duration time.Duration) *Config {
3✔
171
        conf.PresignExpire = duration
3✔
172
        return conf
3✔
173
}
3✔
174

175
func (conf *Config) SetPresignHostname(hostname string) *Config {
3✔
176
        conf.PresignHostname = hostname
3✔
177
        return conf
3✔
178
}
3✔
179

180
func (conf *Config) SetPresignScheme(scheme string) *Config {
3✔
181
        conf.PresignScheme = scheme
3✔
182
        return conf
3✔
183
}
3✔
184

185
func (conf *Config) SetMaxImageSize(size int64) *Config {
2✔
186
        conf.MaxImageSize = size
2✔
187
        return conf
2✔
188
}
2✔
189

190
func (conf *Config) SetMaxGenerateDataSize(size int64) *Config {
2✔
191
        conf.MaxGenerateDataSize = size
2✔
192
        return conf
2✔
193
}
2✔
194

195
func (conf *Config) SetEnableDirectUpload(enable bool) *Config {
3✔
196
        conf.EnableDirectUpload = enable
3✔
197
        return conf
3✔
198
}
3✔
199

200
func (conf *Config) SetEnableDirectUploadSkipVerify(enable bool) *Config {
2✔
201
        conf.EnableDirectUploadSkipVerify = enable
2✔
202
        return conf
2✔
203
}
2✔
204

205
func (conf *Config) SetDisableNewReleasesFeature(disable bool) *Config {
3✔
206
        conf.DisableNewReleasesFeature = disable
3✔
207
        return conf
3✔
208
}
3✔
209

210
type DeploymentsApiHandlers struct {
211
        view   RESTView
212
        store  store.DataStore
213
        app    app.App
214
        config Config
215
}
216

217
func NewDeploymentsApiHandlers(
218
        store store.DataStore,
219
        view RESTView,
220
        app app.App,
221
        config ...*Config,
222
) *DeploymentsApiHandlers {
3✔
223
        conf := NewConfig()
3✔
224
        for _, c := range config {
6✔
225
                if c == nil {
4✔
226
                        continue
1✔
227
                }
228
                if c.PresignSecret != nil {
6✔
229
                        conf.PresignSecret = c.PresignSecret
3✔
230
                }
3✔
231
                if c.PresignExpire != 0 {
6✔
232
                        conf.PresignExpire = c.PresignExpire
3✔
233
                }
3✔
234
                if c.PresignHostname != "" {
6✔
235
                        conf.PresignHostname = c.PresignHostname
3✔
236
                }
3✔
237
                if c.PresignScheme != "" {
6✔
238
                        conf.PresignScheme = c.PresignScheme
3✔
239
                }
3✔
240
                if c.MaxImageSize > 0 {
6✔
241
                        conf.MaxImageSize = c.MaxImageSize
3✔
242
                }
3✔
243
                if c.MaxGenerateDataSize > 0 {
6✔
244
                        conf.MaxGenerateDataSize = c.MaxGenerateDataSize
3✔
245
                }
3✔
246
                conf.DisableNewReleasesFeature = c.DisableNewReleasesFeature
3✔
247
                conf.EnableDirectUpload = c.EnableDirectUpload
3✔
248
                conf.EnableDirectUploadSkipVerify = c.EnableDirectUploadSkipVerify
3✔
249
        }
250
        return &DeploymentsApiHandlers{
3✔
251
                store:  store,
3✔
252
                view:   view,
3✔
253
                app:    app,
3✔
254
                config: *conf,
3✔
255
        }
3✔
256
}
257

258
func (d *DeploymentsApiHandlers) AliveHandler(w rest.ResponseWriter, r *rest.Request) {
2✔
259
        w.WriteHeader(http.StatusNoContent)
2✔
260
}
2✔
261

262
func (d *DeploymentsApiHandlers) HealthHandler(w rest.ResponseWriter, r *rest.Request) {
2✔
263
        ctx := r.Context()
2✔
264
        l := log.FromContext(ctx)
2✔
265
        ctx, cancel := context.WithTimeout(ctx, defaultTimeout)
2✔
266
        defer cancel()
2✔
267

2✔
268
        err := d.app.HealthCheck(ctx)
2✔
269
        if err != nil {
3✔
270
                rest_utils.RestErrWithLog(w, r, l, err, http.StatusServiceUnavailable)
1✔
271
                return
1✔
272
        }
1✔
273
        w.WriteHeader(http.StatusNoContent)
2✔
274
}
275

276
func getReleaseOrImageFilter(r *rest.Request, version listReleasesVersion,
277
        paginated bool) *model.ReleaseOrImageFilter {
3✔
278

3✔
279
        q := r.URL.Query()
3✔
280

3✔
281
        filter := &model.ReleaseOrImageFilter{
3✔
282
                Name:       q.Get(ParamName),
3✔
283
                UpdateType: q.Get(ParamUpdateType),
3✔
284
        }
3✔
285
        if version == listReleasesV1 {
6✔
286
                filter.Description = q.Get(ParamDescription)
3✔
287
                filter.DeviceType = q.Get(ParamDeviceType)
3✔
288
        } else if version == listReleasesV2 {
7✔
289
                filter.Tags = q[ParamTag]
2✔
290
                for i, t := range filter.Tags {
3✔
291
                        filter.Tags[i] = strings.ToLower(t)
1✔
292
                }
1✔
293
        }
294

295
        if paginated {
5✔
296
                filter.Sort = q.Get(ParamSort)
2✔
297
                if page := q.Get(ParamPage); page != "" {
3✔
298
                        if i, err := strconv.Atoi(page); err == nil {
2✔
299
                                filter.Page = i
1✔
300
                        }
1✔
301
                }
302
                if perPage := q.Get(ParamPerPage); perPage != "" {
3✔
303
                        if i, err := strconv.Atoi(perPage); err == nil {
2✔
304
                                filter.PerPage = i
1✔
305
                        }
1✔
306
                }
307
                if filter.Page <= 0 {
4✔
308
                        filter.Page = 1
2✔
309
                }
2✔
310
                if filter.PerPage <= 0 || filter.PerPage > MaximumPerPage {
4✔
311
                        filter.PerPage = DefaultPerPage
2✔
312
                }
2✔
313
        }
314

315
        return filter
3✔
316
}
317

318
type limitResponse struct {
319
        Limit uint64 `json:"limit"`
320
        Usage uint64 `json:"usage"`
321
}
322

323
func (d *DeploymentsApiHandlers) GetLimit(w rest.ResponseWriter, r *rest.Request) {
1✔
324
        l := requestlog.GetRequestLogger(r)
1✔
325

1✔
326
        name := r.PathParam("name")
1✔
327

1✔
328
        if !model.IsValidLimit(name) {
2✔
329
                d.view.RenderError(w, r,
1✔
330
                        errors.Errorf("unsupported limit %s", name),
1✔
331
                        http.StatusBadRequest, l)
1✔
332
                return
1✔
333
        }
1✔
334

335
        limit, err := d.app.GetLimit(r.Context(), name)
1✔
336
        if err != nil {
2✔
337
                d.view.RenderInternalError(w, r, err, l)
1✔
338
                return
1✔
339
        }
1✔
340

341
        d.view.RenderSuccessGet(w, limitResponse{
1✔
342
                Limit: limit.Value,
1✔
343
                Usage: 0, // TODO fill this when ready
1✔
344
        })
1✔
345
}
346

347
// images
348

349
func (d *DeploymentsApiHandlers) GetImage(w rest.ResponseWriter, r *rest.Request) {
2✔
350
        l := requestlog.GetRequestLogger(r)
2✔
351

2✔
352
        id := r.PathParam("id")
2✔
353

2✔
354
        if !govalidator.IsUUID(id) {
3✔
355
                d.view.RenderError(w, r, ErrIDNotUUID, http.StatusBadRequest, l)
1✔
356
                return
1✔
357
        }
1✔
358

359
        image, err := d.app.GetImage(r.Context(), id)
2✔
360
        if err != nil {
2✔
361
                d.view.RenderInternalError(w, r, err, l)
×
362
                return
×
363
        }
×
364

365
        if image == nil {
3✔
366
                d.view.RenderErrorNotFound(w, r, l)
1✔
367
                return
1✔
368
        }
1✔
369

370
        d.view.RenderSuccessGet(w, image)
2✔
371
}
372

373
func (d *DeploymentsApiHandlers) GetImages(w rest.ResponseWriter, r *rest.Request) {
3✔
374
        l := requestlog.GetRequestLogger(r)
3✔
375

3✔
376
        defer redactReleaseName(r)
3✔
377
        filter := getReleaseOrImageFilter(r, listReleasesV1, false)
3✔
378

3✔
379
        list, _, err := d.app.ListImages(r.Context(), filter)
3✔
380
        if err != nil {
4✔
381
                d.view.RenderInternalError(w, r, err, l)
1✔
382
                return
1✔
383
        }
1✔
384

385
        d.view.RenderSuccessGet(w, list)
3✔
386
}
387

388
func (d *DeploymentsApiHandlers) ListImages(w rest.ResponseWriter, r *rest.Request) {
1✔
389
        l := requestlog.GetRequestLogger(r)
1✔
390

1✔
391
        defer redactReleaseName(r)
1✔
392
        filter := getReleaseOrImageFilter(r, listReleasesV1, true)
1✔
393

1✔
394
        list, totalCount, err := d.app.ListImages(r.Context(), filter)
1✔
395
        if err != nil {
2✔
396
                d.view.RenderInternalError(w, r, err, l)
1✔
397
                return
1✔
398
        }
1✔
399

400
        hasNext := totalCount > int(filter.Page*filter.PerPage)
1✔
401
        links := rest_utils.MakePageLinkHdrs(r, uint64(filter.Page), uint64(filter.PerPage), hasNext)
1✔
402
        for _, l := range links {
2✔
403
                w.Header().Add(hdrLink, l)
1✔
404
        }
1✔
405
        w.Header().Add(hdrTotalCount, strconv.Itoa(totalCount))
1✔
406

1✔
407
        d.view.RenderSuccessGet(w, list)
1✔
408
}
409

410
func (d *DeploymentsApiHandlers) DownloadLink(w rest.ResponseWriter, r *rest.Request) {
1✔
411
        l := requestlog.GetRequestLogger(r)
1✔
412

1✔
413
        id := r.PathParam("id")
1✔
414

1✔
415
        if !govalidator.IsUUID(id) {
1✔
416
                d.view.RenderError(w, r, ErrIDNotUUID, http.StatusBadRequest, l)
×
417
                return
×
418
        }
×
419

420
        expireSeconds := config.Config.GetInt(dconfig.SettingsStorageDownloadExpireSeconds)
1✔
421
        link, err := d.app.DownloadLink(r.Context(), id, time.Duration(expireSeconds)*time.Second)
1✔
422
        if err != nil {
1✔
423
                d.view.RenderInternalError(w, r, err, l)
×
424
                return
×
425
        }
×
426

427
        if link == nil {
1✔
428
                d.view.RenderErrorNotFound(w, r, l)
×
429
                return
×
430
        }
×
431

432
        d.view.RenderSuccessGet(w, link)
1✔
433
}
434

435
func (d *DeploymentsApiHandlers) UploadLink(w rest.ResponseWriter, r *rest.Request) {
2✔
436
        l := requestlog.GetRequestLogger(r)
2✔
437

2✔
438
        expireSeconds := config.Config.GetInt(dconfig.SettingsStorageUploadExpireSeconds)
2✔
439
        link, err := d.app.UploadLink(
2✔
440
                r.Context(),
2✔
441
                time.Duration(expireSeconds)*time.Second,
2✔
442
                d.config.EnableDirectUploadSkipVerify,
2✔
443
        )
2✔
444
        if err != nil {
3✔
445
                d.view.RenderInternalError(w, r, err, l)
1✔
446
                return
1✔
447
        }
1✔
448

449
        if link == nil {
3✔
450
                d.view.RenderErrorNotFound(w, r, l)
1✔
451
                return
1✔
452
        }
1✔
453

454
        d.view.RenderSuccessGet(w, link)
2✔
455
}
456

457
const maxMetadataSize = 2048
458

459
func (d *DeploymentsApiHandlers) CompleteUpload(w rest.ResponseWriter, r *rest.Request) {
2✔
460
        ctx := r.Context()
2✔
461
        l := log.FromContext(ctx)
2✔
462

2✔
463
        artifactID := r.PathParam(ParamID)
2✔
464

2✔
465
        var metadata *model.DirectUploadMetadata
2✔
466
        if d.config.EnableDirectUploadSkipVerify {
3✔
467
                var directMetadata model.DirectUploadMetadata
1✔
468
                bodyBuffer := make([]byte, maxMetadataSize)
1✔
469
                n, err := io.ReadFull(r.Body, bodyBuffer)
1✔
470
                r.Body.Close()
1✔
471
                if err != nil && err != io.EOF && err != io.ErrUnexpectedEOF {
1✔
472
                        l.Errorf("error reading post body data: %s (read: %d)", err.Error(), n)
×
473
                } else {
1✔
474
                        err = json.Unmarshal(bodyBuffer[:n], &directMetadata)
1✔
475
                        if err == nil {
2✔
476
                                if directMetadata.Validate() == nil {
2✔
477
                                        metadata = &directMetadata
1✔
478
                                }
1✔
479
                        } else {
1✔
480
                                l.Errorf("error parsing json data: %s", err.Error())
1✔
481
                        }
1✔
482
                }
483
        }
484

485
        err := d.app.CompleteUpload(ctx, artifactID, d.config.EnableDirectUploadSkipVerify, metadata)
2✔
486
        switch errors.Cause(err) {
2✔
487
        case nil:
2✔
488
                // w.Header().Set("Link", "FEAT: Upload status API")
2✔
489
                w.WriteHeader(http.StatusAccepted)
2✔
490
        case app.ErrUploadNotFound:
1✔
491
                d.view.RenderErrorNotFound(w, r, l)
1✔
492
        default:
1✔
493
                l.Error(err)
1✔
494
                w.WriteHeader(http.StatusInternalServerError)
1✔
495
                w.WriteJson(rest_utils.ApiError{ // nolint:errcheck
1✔
496
                        Err:   "internal server error",
1✔
497
                        ReqId: requestid.FromContext(ctx),
1✔
498
                })
1✔
499
        }
500
}
501

502
func (d *DeploymentsApiHandlers) DownloadConfiguration(w rest.ResponseWriter, r *rest.Request) {
3✔
503
        if d.config.PresignSecret == nil {
4✔
504
                rest.NotFound(w, r)
1✔
505
                return
1✔
506
        }
1✔
507
        var (
3✔
508
                deviceID, _     = url.PathUnescape(r.PathParam(ParamDeviceID))
3✔
509
                deviceType, _   = url.PathUnescape(r.PathParam(ParamDeviceType))
3✔
510
                deploymentID, _ = url.PathUnescape(r.PathParam(ParamDeploymentID))
3✔
511
        )
3✔
512
        if deviceID == "" || deviceType == "" || deploymentID == "" {
3✔
513
                rest.NotFound(w, r)
×
514
                return
×
515
        }
×
516

517
        var (
3✔
518
                tenantID string
3✔
519
                l        = log.FromContext(r.Context())
3✔
520
                q        = r.URL.Query()
3✔
521
                err      error
3✔
522
        )
3✔
523
        tenantID = q.Get(ParamTenantID)
3✔
524
        sig := model.NewRequestSignature(r.Request, d.config.PresignSecret)
3✔
525
        if err = sig.Validate(); err != nil {
6✔
526
                switch cause := errors.Cause(err); cause {
3✔
527
                case model.ErrLinkExpired:
1✔
528
                        d.view.RenderError(w, r, cause, http.StatusForbidden, l)
1✔
529
                default:
3✔
530
                        d.view.RenderError(w, r,
3✔
531
                                errors.Wrap(err, "invalid request parameters"),
3✔
532
                                http.StatusBadRequest, l,
3✔
533
                        )
3✔
534
                }
535
                return
3✔
536
        }
537

538
        if !sig.VerifyHMAC256() {
4✔
539
                d.view.RenderError(w, r,
2✔
540
                        errors.New("signature invalid"),
2✔
541
                        http.StatusForbidden, l,
2✔
542
                )
2✔
543
                return
2✔
544
        }
2✔
545

546
        // Validate request signature
547
        ctx := identity.WithContext(r.Context(), &identity.Identity{
2✔
548
                Subject:  deviceID,
2✔
549
                Tenant:   tenantID,
2✔
550
                IsDevice: true,
2✔
551
        })
2✔
552

2✔
553
        artifact, err := d.app.GenerateConfigurationImage(ctx, deviceType, deploymentID)
2✔
554
        if err != nil {
3✔
555
                switch cause := errors.Cause(err); cause {
1✔
556
                case app.ErrModelDeploymentNotFound:
1✔
557
                        d.view.RenderError(w, r,
1✔
558
                                errors.Errorf(
1✔
559
                                        "deployment with id '%s' not found",
1✔
560
                                        deploymentID,
1✔
561
                                ),
1✔
562
                                http.StatusNotFound, l,
1✔
563
                        )
1✔
564
                default:
1✔
565
                        l.Error(err.Error())
1✔
566
                        d.view.RenderInternalError(w, r, err, l)
1✔
567
                }
568
                return
1✔
569
        }
570
        artifactPayload, err := io.ReadAll(artifact)
2✔
571
        if err != nil {
3✔
572
                l.Error(err.Error())
1✔
573
                d.view.RenderInternalError(w, r, err, l)
1✔
574
                return
1✔
575
        }
1✔
576

577
        rw := w.(http.ResponseWriter)
2✔
578
        hdr := rw.Header()
2✔
579
        hdr.Set("Content-Disposition", `attachment; filename="artifact.mender"`)
2✔
580
        hdr.Set("Content-Type", app.ArtifactContentType)
2✔
581
        hdr.Set("Content-Length", strconv.Itoa(len(artifactPayload)))
2✔
582
        rw.WriteHeader(http.StatusOK)
2✔
583
        _, err = rw.Write(artifactPayload)
2✔
584
        if err != nil {
2✔
585
                // There's not anything we can do here in terms of the response.
×
586
                l.Error(err.Error())
×
587
        }
×
588
}
589

590
func (d *DeploymentsApiHandlers) DeleteImage(w rest.ResponseWriter, r *rest.Request) {
1✔
591
        l := requestlog.GetRequestLogger(r)
1✔
592

1✔
593
        id := r.PathParam("id")
1✔
594

1✔
595
        if !govalidator.IsUUID(id) {
1✔
596
                d.view.RenderError(w, r, ErrIDNotUUID, http.StatusBadRequest, l)
×
597
                return
×
598
        }
×
599

600
        if err := d.app.DeleteImage(r.Context(), id); err != nil {
2✔
601
                switch err {
1✔
602
                default:
×
603
                        d.view.RenderInternalError(w, r, err, l)
×
604
                case app.ErrImageMetaNotFound:
×
605
                        d.view.RenderErrorNotFound(w, r, l)
×
606
                case app.ErrModelImageInActiveDeployment:
1✔
607
                        d.view.RenderError(w, r, ErrArtifactUsedInActiveDeployment, http.StatusConflict, l)
1✔
608
                }
609
                return
1✔
610
        }
611

612
        d.view.RenderSuccessDelete(w)
1✔
613
}
614

615
func (d *DeploymentsApiHandlers) EditImage(w rest.ResponseWriter, r *rest.Request) {
×
616
        l := requestlog.GetRequestLogger(r)
×
617

×
618
        id := r.PathParam("id")
×
619

×
620
        if !govalidator.IsUUID(id) {
×
621
                d.view.RenderError(w, r, ErrIDNotUUID, http.StatusBadRequest, l)
×
622
                return
×
623
        }
×
624

625
        constructor, err := getImageMetaFromBody(r)
×
626
        if err != nil {
×
627
                d.view.RenderError(
×
628
                        w,
×
629
                        r,
×
630
                        errors.Wrap(err, "Validating request body"),
×
631
                        http.StatusBadRequest,
×
632
                        l,
×
633
                )
×
634
                return
×
635
        }
×
636

637
        found, err := d.app.EditImage(r.Context(), id, constructor)
×
638
        if err != nil {
×
639
                if err == app.ErrModelImageUsedInAnyDeployment {
×
640
                        d.view.RenderError(w, r, err, http.StatusUnprocessableEntity, l)
×
641
                        return
×
642
                }
×
643
                d.view.RenderInternalError(w, r, err, l)
×
644
                return
×
645
        }
646

647
        if !found {
×
648
                d.view.RenderErrorNotFound(w, r, l)
×
649
                return
×
650
        }
×
651

652
        d.view.RenderSuccessPut(w)
×
653
}
654

655
func getImageMetaFromBody(r *rest.Request) (*model.ImageMeta, error) {
×
656

×
657
        var constructor *model.ImageMeta
×
658

×
659
        if err := r.DecodeJsonPayload(&constructor); err != nil {
×
660
                return nil, err
×
661
        }
×
662

663
        if err := constructor.Validate(); err != nil {
×
664
                return nil, err
×
665
        }
×
666

667
        return constructor, nil
×
668
}
669

670
// NewImage is the Multipart Image/Meta upload handler.
671
// Request should be of type "multipart/form-data". The parts are
672
// key/value pairs of metadata information except the last one,
673
// which must contain the artifact file.
674
func (d *DeploymentsApiHandlers) NewImage(w rest.ResponseWriter, r *rest.Request) {
3✔
675
        d.newImageWithContext(r.Context(), w, r)
3✔
676
}
3✔
677

678
func (d *DeploymentsApiHandlers) NewImageForTenantHandler(w rest.ResponseWriter, r *rest.Request) {
3✔
679
        l := requestlog.GetRequestLogger(r)
3✔
680

3✔
681
        tenantID := r.PathParam("tenant")
3✔
682

3✔
683
        if tenantID == "" {
3✔
684
                rest_utils.RestErrWithLog(
×
685
                        w,
×
686
                        r,
×
687
                        l,
×
688
                        fmt.Errorf("missing tenant id in path"),
×
689
                        http.StatusBadRequest,
×
690
                )
×
691
                return
×
692
        }
×
693

694
        var ctx context.Context
3✔
695
        if tenantID != "default" {
5✔
696
                ident := &identity.Identity{Tenant: tenantID}
2✔
697
                ctx = identity.WithContext(r.Context(), ident)
2✔
698
        } else {
4✔
699
                ctx = r.Context()
2✔
700
        }
2✔
701

702
        d.newImageWithContext(ctx, w, r)
3✔
703
}
704

705
func (d *DeploymentsApiHandlers) newImageWithContext(
706
        ctx context.Context,
707
        w rest.ResponseWriter,
708
        r *rest.Request,
709
) {
3✔
710
        l := requestlog.GetRequestLogger(r)
3✔
711

3✔
712
        formReader, err := r.MultipartReader()
3✔
713
        if err != nil {
5✔
714
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
2✔
715
                return
2✔
716
        }
2✔
717

718
        // parse multipart message
719
        multipartUploadMsg, err := d.ParseMultipart(formReader)
3✔
720

3✔
721
        if err != nil {
5✔
722
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
2✔
723
                return
2✔
724
        }
2✔
725

726
        imgID, err := d.app.CreateImage(ctx, multipartUploadMsg)
3✔
727
        if err == nil {
6✔
728
                d.view.RenderSuccessPost(w, r, imgID)
3✔
729
                return
3✔
730
        }
3✔
731
        var cErr *model.ConflictError
2✔
732
        if errors.As(err, &cErr) {
3✔
733
                w.WriteHeader(http.StatusConflict)
1✔
734
                _ = cErr.WithRequestID(requestid.FromContext(ctx))
1✔
735
                err = w.WriteJson(cErr)
1✔
736
                if err != nil {
1✔
737
                        l.Error(err)
×
738
                } else {
1✔
739
                        l.Error(cErr.Error())
1✔
740
                }
1✔
741
                return
1✔
742
        }
743
        cause := errors.Cause(err)
1✔
744
        switch cause {
1✔
745
        default:
×
746
                d.view.RenderInternalError(w, r, err, l)
×
747
                return
×
748
        case app.ErrModelArtifactNotUnique:
×
749
                l.Error(err.Error())
×
750
                d.view.RenderError(w, r, cause, http.StatusUnprocessableEntity, l)
×
751
                return
×
752
        case app.ErrModelParsingArtifactFailed:
1✔
753
                l.Error(err.Error())
1✔
754
                d.view.RenderError(w, r, formatArtifactUploadError(err), http.StatusBadRequest, l)
1✔
755
                return
1✔
756
        case utils.ErrStreamTooLarge, ErrModelArtifactFileTooLarge:
×
757
                d.view.RenderError(w, r, ErrModelArtifactFileTooLarge, http.StatusRequestEntityTooLarge, l)
×
758
                return
×
759
        case app.ErrModelMissingInputMetadata, app.ErrModelMissingInputArtifact,
760
                app.ErrModelInvalidMetadata, app.ErrModelMultipartUploadMsgMalformed,
761
                io.ErrUnexpectedEOF:
×
762
                l.Error(err.Error())
×
763
                d.view.RenderError(w, r, cause, http.StatusBadRequest, l)
×
764
                return
×
765
        }
766
}
767

768
func formatArtifactUploadError(err error) error {
2✔
769
        // remove generic message
2✔
770
        errMsg := strings.TrimSuffix(err.Error(), ": "+app.ErrModelParsingArtifactFailed.Error())
2✔
771

2✔
772
        // handle specific cases
2✔
773

2✔
774
        if strings.Contains(errMsg, "invalid checksum") {
2✔
775
                return errors.New(errMsg[strings.Index(errMsg, "invalid checksum"):])
×
776
        }
×
777

778
        if strings.Contains(errMsg, "unsupported version") {
2✔
779
                return errors.New(errMsg[strings.Index(errMsg, "unsupported version"):] +
×
780
                        "; supported versions are: 1, 2")
×
781
        }
×
782

783
        return errors.New(errMsg)
2✔
784
}
785

786
// GenerateImage s the multipart Raw Data/Meta upload handler.
787
// Request should be of type "multipart/form-data". The parts are
788
// key/valyue pairs of metadata information except the last one,
789
// which must contain the file containing the raw data to be processed
790
// into an artifact.
791
func (d *DeploymentsApiHandlers) GenerateImage(w rest.ResponseWriter, r *rest.Request) {
3✔
792
        l := requestlog.GetRequestLogger(r)
3✔
793

3✔
794
        formReader, err := r.MultipartReader()
3✔
795
        if err != nil {
4✔
796
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
1✔
797
                return
1✔
798
        }
1✔
799

800
        // parse multipart message
801
        multipartMsg, err := d.ParseGenerateImageMultipart(formReader)
3✔
802
        if err != nil {
4✔
803
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
1✔
804
                return
1✔
805
        }
1✔
806

807
        tokenFields := strings.Fields(r.Header.Get("Authorization"))
3✔
808
        if len(tokenFields) == 2 && strings.EqualFold(tokenFields[0], "Bearer") {
6✔
809
                multipartMsg.Token = tokenFields[1]
3✔
810
        }
3✔
811

812
        imgID, err := d.app.GenerateImage(r.Context(), multipartMsg)
3✔
813
        cause := errors.Cause(err)
3✔
814
        switch cause {
3✔
815
        default:
1✔
816
                d.view.RenderInternalError(w, r, err, l)
1✔
817
        case nil:
3✔
818
                d.view.RenderSuccessPost(w, r, imgID)
3✔
819
        case app.ErrModelArtifactNotUnique:
1✔
820
                l.Error(err.Error())
1✔
821
                d.view.RenderError(w, r, cause, http.StatusUnprocessableEntity, l)
1✔
822
        case app.ErrModelParsingArtifactFailed:
1✔
823
                l.Error(err.Error())
1✔
824
                d.view.RenderError(w, r, formatArtifactUploadError(err), http.StatusBadRequest, l)
1✔
825
        case utils.ErrStreamTooLarge, ErrModelArtifactFileTooLarge:
1✔
826
                d.view.RenderError(w, r, ErrModelArtifactFileTooLarge, http.StatusRequestEntityTooLarge, l)
1✔
827
        case app.ErrModelMissingInputMetadata, app.ErrModelMissingInputArtifact,
828
                app.ErrModelInvalidMetadata, app.ErrModelMultipartUploadMsgMalformed,
829
                io.ErrUnexpectedEOF:
×
830
                l.Error(err.Error())
×
831
                d.view.RenderError(w, r, cause, http.StatusBadRequest, l)
×
832
        }
833
}
834

835
// ParseMultipart parses multipart/form-data message.
836
func (d *DeploymentsApiHandlers) ParseMultipart(
837
        r *multipart.Reader,
838
) (*model.MultipartUploadMsg, error) {
3✔
839
        uploadMsg := &model.MultipartUploadMsg{
3✔
840
                MetaConstructor: &model.ImageMeta{},
3✔
841
        }
3✔
842
        var size int64
3✔
843
        // Parse the multipart form sequentially. To remain backward compatible
3✔
844
        // all form names that are not part of the API are ignored.
3✔
845
        for {
6✔
846
                part, err := r.NextPart()
3✔
847
                if err != nil {
4✔
848
                        if err == io.EOF {
2✔
849
                                // The whole message has been consumed without
1✔
850
                                // the "artifact" form part.
1✔
851
                                return nil, ErrArtifactFileMissing
1✔
852
                        }
1✔
853
                        return nil, err
×
854
                }
855
                switch strings.ToLower(part.FormName()) {
3✔
856
                case "description":
3✔
857
                        // Add description to the metadata
3✔
858
                        reader := utils.ReadAtMost(part, MaxFormParamSize)
3✔
859
                        dscr, err := io.ReadAll(reader)
3✔
860
                        if err != nil {
3✔
NEW
861
                                return nil, errors.Wrap(err,
×
NEW
862
                                        "failed to read form value 'description'",
×
NEW
863
                                )
×
UNCOV
864
                        }
×
865
                        uploadMsg.MetaConstructor.Description = string(dscr)
3✔
866

867
                case "size":
3✔
868
                        // Add size limit to the metadata
3✔
869
                        reader := utils.ReadAtMost(part, 20)
3✔
870
                        sz, err := io.ReadAll(reader)
3✔
871
                        if err != nil {
4✔
872
                                return nil, errors.Wrap(err,
1✔
873
                                        "failed to read form value 'size'",
1✔
874
                                )
1✔
875
                        }
1✔
876
                        size, err = strconv.ParseInt(string(sz), 10, 64)
3✔
877
                        if err != nil {
3✔
878
                                return nil, err
×
879
                        }
×
880
                        if size > d.config.MaxImageSize {
3✔
881
                                return nil, ErrModelArtifactFileTooLarge
×
882
                        }
×
883

884
                case "artifact_id":
3✔
885
                        // Add artifact id to the metadata (must be a valid UUID).
3✔
886
                        reader := utils.ReadAtMost(part, MaxFormParamSize)
3✔
887
                        b, err := io.ReadAll(reader)
3✔
888
                        if err != nil {
3✔
NEW
889
                                return nil, errors.Wrap(err,
×
NEW
890
                                        "failed to read form value 'artifact_id'",
×
NEW
891
                                )
×
UNCOV
892
                        }
×
893
                        id := string(b)
3✔
894
                        if !govalidator.IsUUID(id) {
5✔
895
                                return nil, errors.New(
2✔
896
                                        "artifact_id is not a valid UUID",
2✔
897
                                )
2✔
898
                        }
2✔
899
                        uploadMsg.ArtifactID = id
2✔
900

901
                case "artifact":
3✔
902
                        // Assign the form-data payload to the artifact reader
3✔
903
                        // and return. The content is consumed elsewhere.
3✔
904
                        if size > 0 {
6✔
905
                                uploadMsg.ArtifactReader = utils.ReadExactly(part, size)
3✔
906
                        } else {
4✔
907
                                uploadMsg.ArtifactReader = utils.ReadAtMost(
1✔
908
                                        part,
1✔
909
                                        d.config.MaxImageSize,
1✔
910
                                )
1✔
911
                        }
1✔
912
                        return uploadMsg, nil
3✔
913

914
                default:
2✔
915
                        // Ignore all non-API sections.
2✔
916
                        continue
2✔
917
                }
918
        }
919
}
920

921
// ParseGenerateImageMultipart parses multipart/form-data message.
922
func (d *DeploymentsApiHandlers) ParseGenerateImageMultipart(
923
        r *multipart.Reader,
924
) (*model.MultipartGenerateImageMsg, error) {
3✔
925
        msg := &model.MultipartGenerateImageMsg{}
3✔
926
        var size int64
3✔
927

3✔
928
ParseLoop:
3✔
929
        for {
6✔
930
                part, err := r.NextPart()
3✔
931
                if err != nil {
4✔
932
                        if err == io.EOF {
2✔
933
                                break
1✔
934
                        }
935
                        return nil, err
×
936
                }
937
                switch strings.ToLower(part.FormName()) {
3✔
938
                case "args":
3✔
939
                        reader := utils.ReadAtMost(part, MaxFormParamSize)
3✔
940
                        b, err := io.ReadAll(reader)
3✔
941
                        if err != nil {
3✔
942
                                return nil, errors.Wrap(err,
×
943
                                        "failed to read form value 'args'",
×
944
                                )
×
945
                        }
×
946
                        msg.Args = string(b)
3✔
947

948
                case "description":
3✔
949
                        reader := utils.ReadAtMost(part, MaxFormParamSize)
3✔
950
                        b, err := io.ReadAll(reader)
3✔
951
                        if err != nil {
3✔
952
                                return nil, errors.Wrap(err,
×
953
                                        "failed to read form value 'description'",
×
954
                                )
×
955
                        }
×
956
                        msg.Description = string(b)
3✔
957

958
                case "device_types_compatible":
3✔
959
                        reader := utils.ReadAtMost(part, MaxFormParamSize)
3✔
960
                        b, err := io.ReadAll(reader)
3✔
961
                        if err != nil {
3✔
962
                                return nil, errors.Wrap(err,
×
963
                                        "failed to read form value 'device_types_compatible'",
×
964
                                )
×
965
                        }
×
966
                        msg.DeviceTypesCompatible = strings.Split(string(b), ",")
3✔
967

968
                case "file":
3✔
969
                        if size > 0 {
4✔
970
                                msg.FileReader = utils.ReadExactly(part, size)
1✔
971
                        } else {
4✔
972
                                msg.FileReader = utils.ReadAtMost(part, d.config.MaxGenerateDataSize)
3✔
973
                        }
3✔
974
                        break ParseLoop
3✔
975

976
                case "name":
3✔
977
                        reader := utils.ReadAtMost(part, MaxFormParamSize)
3✔
978
                        b, err := io.ReadAll(reader)
3✔
979
                        if err != nil {
3✔
980
                                return nil, errors.Wrap(err,
×
981
                                        "failed to read form value 'name'",
×
982
                                )
×
983
                        }
×
984
                        msg.Name = string(b)
3✔
985

986
                case "type":
3✔
987
                        reader := utils.ReadAtMost(part, MaxFormParamSize)
3✔
988
                        b, err := io.ReadAll(reader)
3✔
989
                        if err != nil {
3✔
990
                                return nil, errors.Wrap(err,
×
991
                                        "failed to read form value 'type'",
×
992
                                )
×
993
                        }
×
994
                        msg.Type = string(b)
3✔
995

996
                case "size":
1✔
997
                        // Add size limit to the metadata
1✔
998
                        reader := utils.ReadAtMost(part, 20)
1✔
999
                        sz, err := io.ReadAll(reader)
1✔
1000
                        if err != nil {
2✔
1001
                                return nil, errors.Wrap(err,
1✔
1002
                                        "failed to read form value 'size'",
1✔
1003
                                )
1✔
1004
                        }
1✔
1005
                        size, err = strconv.ParseInt(string(sz), 10, 64)
1✔
1006
                        if err != nil {
1✔
1007
                                return nil, err
×
1008
                        }
×
1009
                        if size > d.config.MaxGenerateDataSize {
1✔
1010
                                return nil, ErrModelArtifactFileTooLarge
×
1011
                        }
×
1012

1013
                default:
×
1014
                        // Ignore non-API sections.
×
1015
                        continue
×
1016
                }
1017
        }
1018

1019
        return msg, errors.Wrap(msg.Validate(), "api: invalid form parameters")
3✔
1020
}
1021

1022
// deployments
1023
func (d *DeploymentsApiHandlers) createDeployment(
1024
        w rest.ResponseWriter,
1025
        r *rest.Request,
1026
        ctx context.Context,
1027
        l *log.Logger,
1028
        group string,
1029
) {
3✔
1030
        constructor, err := d.getDeploymentConstructorFromBody(r, group)
3✔
1031
        if err != nil {
6✔
1032
                d.view.RenderError(
3✔
1033
                        w,
3✔
1034
                        r,
3✔
1035
                        errors.Wrap(err, "Validating request body"),
3✔
1036
                        http.StatusBadRequest,
3✔
1037
                        l,
3✔
1038
                )
3✔
1039
                return
3✔
1040
        }
3✔
1041

1042
        id, err := d.app.CreateDeployment(ctx, constructor)
3✔
1043
        switch err {
3✔
1044
        case nil:
3✔
1045
                // in case of deployment to group remove "/group/{name}" from path before creating location
3✔
1046
                // haeder
3✔
1047
                r.URL.Path = strings.TrimSuffix(r.URL.Path, "/group/"+constructor.Group)
3✔
1048
                d.view.RenderSuccessPost(w, r, id)
3✔
1049
        case app.ErrNoArtifact:
1✔
1050
                d.view.RenderError(w, r, err, http.StatusUnprocessableEntity, l)
1✔
1051
        case app.ErrNoDevices:
1✔
1052
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
1✔
1053
        case app.ErrConflictingDeployment:
2✔
1054
                d.view.RenderError(w, r, err, http.StatusConflict, l)
2✔
1055
        default:
1✔
1056
                d.view.RenderInternalError(w, r, err, l)
1✔
1057
        }
1058
}
1059

1060
func (d *DeploymentsApiHandlers) PostDeployment(w rest.ResponseWriter, r *rest.Request) {
3✔
1061
        ctx := r.Context()
3✔
1062
        l := requestlog.GetRequestLogger(r)
3✔
1063

3✔
1064
        d.createDeployment(w, r, ctx, l, "")
3✔
1065
}
3✔
1066

1067
func (d *DeploymentsApiHandlers) DeployToGroup(w rest.ResponseWriter, r *rest.Request) {
2✔
1068
        ctx := r.Context()
2✔
1069
        l := requestlog.GetRequestLogger(r)
2✔
1070

2✔
1071
        group := r.PathParam("name")
2✔
1072
        if len(group) < 1 {
2✔
1073
                d.view.RenderError(w, r, ErrMissingGroupName, http.StatusBadRequest, l)
×
1074
        }
×
1075
        d.createDeployment(w, r, ctx, l, group)
2✔
1076
}
1077

1078
// parseDeviceConfigurationDeploymentPathParams parses expected params
1079
// and check if the params are not empty
1080
func parseDeviceConfigurationDeploymentPathParams(r *rest.Request) (string, string, string, error) {
3✔
1081
        tenantID := r.PathParam("tenant")
3✔
1082
        deviceID := r.PathParam(ParamDeviceID)
3✔
1083
        if deviceID == "" {
3✔
1084
                return "", "", "", errors.New("device ID missing")
×
1085
        }
×
1086
        deploymentID := r.PathParam(ParamDeploymentID)
3✔
1087
        if deploymentID == "" {
3✔
1088
                return "", "", "", errors.New("deployment ID missing")
×
1089
        }
×
1090
        return tenantID, deviceID, deploymentID, nil
3✔
1091
}
1092

1093
// getConfigurationDeploymentConstructorFromBody extracts configuration
1094
// deployment constructor from the request body and validates it
1095
func getConfigurationDeploymentConstructorFromBody(r *rest.Request) (
1096
        *model.ConfigurationDeploymentConstructor, error) {
3✔
1097

3✔
1098
        var constructor *model.ConfigurationDeploymentConstructor
3✔
1099

3✔
1100
        if err := r.DecodeJsonPayload(&constructor); err != nil {
5✔
1101
                return nil, err
2✔
1102
        }
2✔
1103

1104
        if err := constructor.Validate(); err != nil {
4✔
1105
                return nil, err
2✔
1106
        }
2✔
1107

1108
        return constructor, nil
2✔
1109
}
1110

1111
// device configuration deployment handler
1112
func (d *DeploymentsApiHandlers) PostDeviceConfigurationDeployment(
1113
        w rest.ResponseWriter,
1114
        r *rest.Request,
1115
) {
3✔
1116
        l := requestlog.GetRequestLogger(r)
3✔
1117

3✔
1118
        // get path params
3✔
1119
        tenantID, deviceID, deploymentID, err := parseDeviceConfigurationDeploymentPathParams(r)
3✔
1120
        if err != nil {
3✔
1121
                rest_utils.RestErrWithLog(w, r, l, err, http.StatusBadRequest)
×
1122
                return
×
1123
        }
×
1124

1125
        // add tenant id to the context
1126
        ctx := identity.WithContext(r.Context(), &identity.Identity{Tenant: tenantID})
3✔
1127

3✔
1128
        constructor, err := getConfigurationDeploymentConstructorFromBody(r)
3✔
1129
        if err != nil {
6✔
1130
                d.view.RenderError(
3✔
1131
                        w,
3✔
1132
                        r,
3✔
1133
                        errors.Wrap(err, "Validating request body"),
3✔
1134
                        http.StatusBadRequest,
3✔
1135
                        l,
3✔
1136
                )
3✔
1137
                return
3✔
1138
        }
3✔
1139

1140
        id, err := d.app.CreateDeviceConfigurationDeployment(ctx, constructor, deviceID, deploymentID)
2✔
1141
        switch err {
2✔
1142
        default:
1✔
1143
                d.view.RenderInternalError(w, r, err, l)
1✔
1144
        case nil:
2✔
1145
                r.URL.Path = "./deployments"
2✔
1146
                d.view.RenderSuccessPost(w, r, id)
2✔
1147
        case app.ErrDuplicateDeployment:
2✔
1148
                d.view.RenderError(w, r, err, http.StatusConflict, l)
2✔
1149
        case app.ErrInvalidDeploymentID:
1✔
1150
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
1✔
1151
        }
1152
}
1153

1154
func (d *DeploymentsApiHandlers) getDeploymentConstructorFromBody(
1155
        r *rest.Request,
1156
        group string,
1157
) (*model.DeploymentConstructor, error) {
3✔
1158
        var constructor *model.DeploymentConstructor
3✔
1159
        if err := r.DecodeJsonPayload(&constructor); err != nil {
5✔
1160
                return nil, err
2✔
1161
        }
2✔
1162

1163
        constructor.Group = group
3✔
1164

3✔
1165
        if err := constructor.ValidateNew(); err != nil {
6✔
1166
                return nil, err
3✔
1167
        }
3✔
1168

1169
        return constructor, nil
3✔
1170
}
1171

1172
func (d *DeploymentsApiHandlers) GetDeployment(w rest.ResponseWriter, r *rest.Request) {
2✔
1173
        ctx := r.Context()
2✔
1174
        l := requestlog.GetRequestLogger(r)
2✔
1175

2✔
1176
        id := r.PathParam("id")
2✔
1177

2✔
1178
        if !govalidator.IsUUID(id) {
3✔
1179
                d.view.RenderError(w, r, ErrIDNotUUID, http.StatusBadRequest, l)
1✔
1180
                return
1✔
1181
        }
1✔
1182

1183
        deployment, err := d.app.GetDeployment(ctx, id)
2✔
1184
        if err != nil {
2✔
1185
                d.view.RenderInternalError(w, r, err, l)
×
1186
                return
×
1187
        }
×
1188

1189
        if deployment == nil {
2✔
1190
                d.view.RenderErrorNotFound(w, r, l)
×
1191
                return
×
1192
        }
×
1193

1194
        d.view.RenderSuccessGet(w, deployment)
2✔
1195
}
1196

1197
func (d *DeploymentsApiHandlers) GetDeploymentStats(w rest.ResponseWriter, r *rest.Request) {
1✔
1198
        ctx := r.Context()
1✔
1199
        l := requestlog.GetRequestLogger(r)
1✔
1200

1✔
1201
        id := r.PathParam("id")
1✔
1202

1✔
1203
        if !govalidator.IsUUID(id) {
1✔
1204
                d.view.RenderError(w, r, ErrIDNotUUID, http.StatusBadRequest, l)
×
1205
                return
×
1206
        }
×
1207

1208
        stats, err := d.app.GetDeploymentStats(ctx, id)
1✔
1209
        if err != nil {
1✔
1210
                d.view.RenderInternalError(w, r, err, l)
×
1211
                return
×
1212
        }
×
1213

1214
        if stats == nil {
1✔
1215
                d.view.RenderErrorNotFound(w, r, l)
×
1216
                return
×
1217
        }
×
1218

1219
        d.view.RenderSuccessGet(w, stats)
1✔
1220
}
1221

1222
func (d *DeploymentsApiHandlers) GetDeploymentsStats(w rest.ResponseWriter, r *rest.Request) {
1✔
1223

1✔
1224
        ctx := r.Context()
1✔
1225
        l := requestlog.GetRequestLogger(r)
1✔
1226

1✔
1227
        ids := model.DeploymentIDs{}
1✔
1228
        if err := r.DecodeJsonPayload(&ids); err != nil {
1✔
1229
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
×
1230
                return
×
1231
        }
×
1232

1233
        if len(ids.IDs) == 0 {
1✔
1234
                w.WriteHeader(http.StatusOK)
×
1235
                _ = w.WriteJson(struct{}{})
×
1236
                return
×
1237
        }
×
1238

1239
        if err := ids.Validate(); err != nil {
2✔
1240
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
1✔
1241
                return
1✔
1242
        }
1✔
1243

1244
        stats, err := d.app.GetDeploymentsStats(ctx, ids.IDs...)
1✔
1245
        if err != nil {
2✔
1246
                if errors.Is(err, app.ErrModelDeploymentNotFound) {
2✔
1247
                        d.view.RenderError(w, r, err, http.StatusNotFound, l)
1✔
1248
                        return
1✔
1249
                }
1✔
1250
                d.view.RenderInternalError(w, r, err, l)
1✔
1251
                return
1✔
1252
        }
1253

1254
        w.WriteHeader(http.StatusOK)
1✔
1255

1✔
1256
        _ = w.WriteJson(stats)
1✔
1257
}
1258

1259
func (d *DeploymentsApiHandlers) GetDeploymentDeviceList(w rest.ResponseWriter, r *rest.Request) {
×
1260
        ctx := r.Context()
×
1261
        l := requestlog.GetRequestLogger(r)
×
1262

×
1263
        id := r.PathParam("id")
×
1264

×
1265
        if !govalidator.IsUUID(id) {
×
1266
                d.view.RenderError(w, r, ErrIDNotUUID, http.StatusBadRequest, l)
×
1267
                return
×
1268
        }
×
1269

1270
        deployment, err := d.app.GetDeployment(ctx, id)
×
1271
        if err != nil {
×
1272
                d.view.RenderInternalError(w, r, err, l)
×
1273
                return
×
1274
        }
×
1275

1276
        if deployment == nil {
×
1277
                d.view.RenderErrorNotFound(w, r, l)
×
1278
                return
×
1279
        }
×
1280

1281
        d.view.RenderSuccessGet(w, deployment.DeviceList)
×
1282
}
1283

1284
func (d *DeploymentsApiHandlers) AbortDeployment(w rest.ResponseWriter, r *rest.Request) {
1✔
1285
        ctx := r.Context()
1✔
1286
        l := requestlog.GetRequestLogger(r)
1✔
1287

1✔
1288
        id := r.PathParam("id")
1✔
1289

1✔
1290
        if !govalidator.IsUUID(id) {
1✔
1291
                d.view.RenderError(w, r, ErrIDNotUUID, http.StatusBadRequest, l)
×
1292
                return
×
1293
        }
×
1294

1295
        // receive request body
1296
        var status struct {
1✔
1297
                Status model.DeviceDeploymentStatus
1✔
1298
        }
1✔
1299

1✔
1300
        err := r.DecodeJsonPayload(&status)
1✔
1301
        if err != nil {
1✔
1302
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
×
1303
                return
×
1304
        }
×
1305
        // "aborted" is the only supported status
1306
        if status.Status != model.DeviceDeploymentStatusAborted {
1✔
1307
                d.view.RenderError(w, r, ErrUnexpectedDeploymentStatus, http.StatusBadRequest, l)
×
1308
        }
×
1309

1310
        l.Infof("Abort deployment: %s", id)
1✔
1311

1✔
1312
        // Check if deployment is finished
1✔
1313
        isDeploymentFinished, err := d.app.IsDeploymentFinished(ctx, id)
1✔
1314
        if err != nil {
1✔
1315
                d.view.RenderInternalError(w, r, err, l)
×
1316
                return
×
1317
        }
×
1318
        if isDeploymentFinished {
2✔
1319
                d.view.RenderError(w, r, ErrDeploymentAlreadyFinished, http.StatusUnprocessableEntity, l)
1✔
1320
                return
1✔
1321
        }
1✔
1322

1323
        // Abort deployments for devices and update deployment stats
1324
        if err := d.app.AbortDeployment(ctx, id); err != nil {
1✔
1325
                d.view.RenderInternalError(w, r, err, l)
×
1326
        }
×
1327

1328
        d.view.RenderEmptySuccessResponse(w)
1✔
1329
}
1330

1331
func (d *DeploymentsApiHandlers) GetDeploymentForDevice(w rest.ResponseWriter, r *rest.Request) {
3✔
1332
        var (
3✔
1333
                installed *model.InstalledDeviceDeployment
3✔
1334
                ctx       = r.Context()
3✔
1335
                l         = requestlog.GetRequestLogger(r)
3✔
1336
                idata     = identity.FromContext(ctx)
3✔
1337
        )
3✔
1338
        if idata == nil {
5✔
1339
                d.view.RenderError(w, r, ErrMissingIdentity, http.StatusBadRequest, l)
2✔
1340
                return
2✔
1341
        }
2✔
1342

1343
        q := r.URL.Query()
3✔
1344
        defer func() {
6✔
1345
                var reEncode bool = false
3✔
1346
                if name := q.Get(ParamArtifactName); name != "" {
6✔
1347
                        q.Set(ParamArtifactName, Redacted)
3✔
1348
                        reEncode = true
3✔
1349
                }
3✔
1350
                if typ := q.Get(ParamDeviceType); typ != "" {
6✔
1351
                        q.Set(ParamDeviceType, Redacted)
3✔
1352
                        reEncode = true
3✔
1353
                }
3✔
1354
                if reEncode {
6✔
1355
                        r.URL.RawQuery = q.Encode()
3✔
1356
                }
3✔
1357
        }()
1358
        if strings.EqualFold(r.Method, http.MethodPost) {
5✔
1359
                // POST
2✔
1360
                installed = new(model.InstalledDeviceDeployment)
2✔
1361
                if err := r.DecodeJsonPayload(&installed); err != nil {
3✔
1362
                        d.view.RenderError(w, r,
1✔
1363
                                errors.Wrap(err, "invalid schema"),
1✔
1364
                                http.StatusBadRequest, l)
1✔
1365
                        return
1✔
1366
                }
1✔
1367
        } else {
3✔
1368
                // GET or HEAD
3✔
1369
                installed = &model.InstalledDeviceDeployment{
3✔
1370
                        ArtifactName: q.Get(ParamArtifactName),
3✔
1371
                        DeviceType:   q.Get(ParamDeviceType),
3✔
1372
                }
3✔
1373
        }
3✔
1374

1375
        if err := installed.Validate(); err != nil {
4✔
1376
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
1✔
1377
                return
1✔
1378
        }
1✔
1379

1380
        request := &model.DeploymentNextRequest{
3✔
1381
                DeviceProvides: installed,
3✔
1382
        }
3✔
1383

3✔
1384
        d.getDeploymentForDevice(w, r, idata, request)
3✔
1385
}
1386

1387
func (d *DeploymentsApiHandlers) getDeploymentForDevice(
1388
        w rest.ResponseWriter,
1389
        r *rest.Request,
1390
        idata *identity.Identity,
1391
        request *model.DeploymentNextRequest,
1392
) {
3✔
1393
        ctx := r.Context()
3✔
1394
        l := requestlog.GetRequestLogger(r)
3✔
1395

3✔
1396
        deployment, err := d.app.GetDeploymentForDeviceWithCurrent(ctx, idata.Subject, request)
3✔
1397
        if err != nil {
5✔
1398
                if err == app.ErrConflictingRequestData {
3✔
1399
                        d.view.RenderError(w, r, err, http.StatusConflict, l)
1✔
1400
                } else {
2✔
1401
                        d.view.RenderInternalError(w, r, err, l)
1✔
1402
                }
1✔
1403
                return
2✔
1404
        }
1405

1406
        if deployment == nil {
6✔
1407
                d.view.RenderNoUpdateForDevice(w)
3✔
1408
                return
3✔
1409
        } else if deployment.Type == model.DeploymentTypeConfiguration {
8✔
1410
                // Generate pre-signed URL
2✔
1411
                var hostName string = d.config.PresignHostname
2✔
1412
                if hostName == "" {
3✔
1413
                        if hostName = r.Header.Get(hdrForwardedHost); hostName == "" {
2✔
1414
                                d.view.RenderInternalError(w, r,
1✔
1415
                                        errors.New("presign.hostname not configured; "+
1✔
1416
                                                "unable to generate download link "+
1✔
1417
                                                " for configuration deployment"), l)
1✔
1418
                                return
1✔
1419
                        }
1✔
1420
                }
1421
                req, _ := http.NewRequest(
2✔
1422
                        http.MethodGet,
2✔
1423
                        FMTConfigURL(
2✔
1424
                                d.config.PresignScheme, hostName,
2✔
1425
                                deployment.ID, request.DeviceProvides.DeviceType,
2✔
1426
                                idata.Subject,
2✔
1427
                        ),
2✔
1428
                        nil,
2✔
1429
                )
2✔
1430
                if idata.Tenant != "" {
4✔
1431
                        q := req.URL.Query()
2✔
1432
                        q.Set(model.ParamTenantID, idata.Tenant)
2✔
1433
                        req.URL.RawQuery = q.Encode()
2✔
1434
                }
2✔
1435
                sig := model.NewRequestSignature(req, d.config.PresignSecret)
2✔
1436
                expireTS := time.Now().Add(d.config.PresignExpire)
2✔
1437
                sig.SetExpire(expireTS)
2✔
1438
                deployment.Artifact.Source = model.Link{
2✔
1439
                        Uri:    sig.PresignURL(),
2✔
1440
                        Expire: expireTS,
2✔
1441
                }
2✔
1442
        }
1443

1444
        d.view.RenderSuccessGet(w, deployment)
3✔
1445
}
1446

1447
func (d *DeploymentsApiHandlers) PutDeploymentStatusForDevice(
1448
        w rest.ResponseWriter,
1449
        r *rest.Request,
1450
) {
2✔
1451
        ctx := r.Context()
2✔
1452
        l := requestlog.GetRequestLogger(r)
2✔
1453

2✔
1454
        did := r.PathParam("id")
2✔
1455

2✔
1456
        idata := identity.FromContext(ctx)
2✔
1457
        if idata == nil {
2✔
1458
                d.view.RenderError(w, r, ErrMissingIdentity, http.StatusBadRequest, l)
×
1459
                return
×
1460
        }
×
1461

1462
        // receive request body
1463
        var report model.StatusReport
2✔
1464

2✔
1465
        err := r.DecodeJsonPayload(&report)
2✔
1466
        if err != nil {
3✔
1467
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
1✔
1468
                return
1✔
1469
        }
1✔
1470

1471
        l.Infof("status: %+v", report)
2✔
1472
        if err := d.app.UpdateDeviceDeploymentStatus(ctx, did,
2✔
1473
                idata.Subject, model.DeviceDeploymentState{
2✔
1474
                        Status:   report.Status,
2✔
1475
                        SubState: report.SubState,
2✔
1476
                }); err != nil {
3✔
1477

1✔
1478
                if err == app.ErrDeploymentAborted || err == app.ErrDeviceDecommissioned {
1✔
1479
                        d.view.RenderError(w, r, err, http.StatusConflict, l)
×
1480
                } else if err == app.ErrStorageNotFound {
2✔
1481
                        d.view.RenderErrorNotFound(w, r, l)
1✔
1482
                } else {
1✔
1483
                        d.view.RenderInternalError(w, r, err, l)
×
1484
                }
×
1485
                return
1✔
1486
        }
1487

1488
        d.view.RenderEmptySuccessResponse(w)
2✔
1489
}
1490

1491
func (d *DeploymentsApiHandlers) GetDeviceStatusesForDeployment(
1492
        w rest.ResponseWriter,
1493
        r *rest.Request,
1494
) {
2✔
1495
        ctx := r.Context()
2✔
1496
        l := requestlog.GetRequestLogger(r)
2✔
1497

2✔
1498
        did := r.PathParam("id")
2✔
1499

2✔
1500
        if !govalidator.IsUUID(did) {
2✔
1501
                d.view.RenderError(w, r, ErrIDNotUUID, http.StatusBadRequest, l)
×
1502
                return
×
1503
        }
×
1504

1505
        statuses, err := d.app.GetDeviceStatusesForDeployment(ctx, did)
2✔
1506
        if err != nil {
2✔
1507
                switch err {
×
1508
                case app.ErrModelDeploymentNotFound:
×
1509
                        d.view.RenderError(w, r, err, http.StatusNotFound, l)
×
1510
                        return
×
1511
                default:
×
1512
                        d.view.RenderInternalError(w, r, ErrInternal, l)
×
1513
                        return
×
1514
                }
1515
        }
1516

1517
        d.view.RenderSuccessGet(w, statuses)
2✔
1518
}
1519

1520
func (d *DeploymentsApiHandlers) GetDevicesListForDeployment(
1521
        w rest.ResponseWriter,
1522
        r *rest.Request,
1523
) {
1✔
1524
        ctx := r.Context()
1✔
1525
        l := requestlog.GetRequestLogger(r)
1✔
1526

1✔
1527
        did := r.PathParam("id")
1✔
1528

1✔
1529
        if !govalidator.IsUUID(did) {
1✔
1530
                d.view.RenderError(w, r, ErrIDNotUUID, http.StatusBadRequest, l)
×
1531
                return
×
1532
        }
×
1533

1534
        page, perPage, err := rest_utils.ParsePagination(r)
1✔
1535
        if err != nil {
1✔
1536
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
×
1537
                return
×
1538
        }
×
1539

1540
        lq := store.ListQuery{
1✔
1541
                Skip:         int((page - 1) * perPage),
1✔
1542
                Limit:        int(perPage),
1✔
1543
                DeploymentID: did,
1✔
1544
        }
1✔
1545
        if status := r.URL.Query().Get("status"); status != "" {
1✔
1546
                lq.Status = &status
×
1547
        }
×
1548
        if err = lq.Validate(); err != nil {
1✔
1549
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
×
1550
                return
×
1551
        }
×
1552

1553
        statuses, totalCount, err := d.app.GetDevicesListForDeployment(ctx, lq)
1✔
1554
        if err != nil {
1✔
1555
                switch err {
×
1556
                case app.ErrModelDeploymentNotFound:
×
1557
                        d.view.RenderError(w, r, err, http.StatusNotFound, l)
×
1558
                        return
×
1559
                default:
×
1560
                        d.view.RenderInternalError(w, r, ErrInternal, l)
×
1561
                        return
×
1562
                }
1563
        }
1564

1565
        hasNext := totalCount > int(page*perPage)
1✔
1566
        links := rest_utils.MakePageLinkHdrs(r, page, perPage, hasNext)
1✔
1567
        for _, l := range links {
2✔
1568
                w.Header().Add(hdrLink, l)
1✔
1569
        }
1✔
1570
        w.Header().Add(hdrTotalCount, strconv.Itoa(totalCount))
1✔
1571
        d.view.RenderSuccessGet(w, statuses)
1✔
1572
}
1573

1574
func ParseLookupQuery(vals url.Values) (model.Query, error) {
3✔
1575
        query := model.Query{}
3✔
1576

3✔
1577
        createdBefore := vals.Get("created_before")
3✔
1578
        if createdBefore != "" {
5✔
1579
                if createdBeforeTime, err := parseEpochToTimestamp(createdBefore); err != nil {
3✔
1580
                        return query, errors.Wrap(err, "timestamp parsing failed for created_before parameter")
1✔
1581
                } else {
2✔
1582
                        query.CreatedBefore = &createdBeforeTime
1✔
1583
                }
1✔
1584
        }
1585

1586
        createdAfter := vals.Get("created_after")
3✔
1587
        if createdAfter != "" {
4✔
1588
                if createdAfterTime, err := parseEpochToTimestamp(createdAfter); err != nil {
1✔
1589
                        return query, errors.Wrap(err, "timestamp parsing failed created_after parameter")
×
1590
                } else {
1✔
1591
                        query.CreatedAfter = &createdAfterTime
1✔
1592
                }
1✔
1593
        }
1594

1595
        switch strings.ToLower(vals.Get("sort")) {
3✔
1596
        case model.SortDirectionAscending:
1✔
1597
                query.Sort = model.SortDirectionAscending
1✔
1598
        case "", model.SortDirectionDescending:
3✔
1599
                query.Sort = model.SortDirectionDescending
3✔
1600
        default:
×
1601
                return query, ErrInvalidSortDirection
×
1602
        }
1603

1604
        status := vals.Get("status")
3✔
1605
        switch status {
3✔
1606
        case "inprogress":
×
1607
                query.Status = model.StatusQueryInProgress
×
1608
        case "finished":
×
1609
                query.Status = model.StatusQueryFinished
×
1610
        case "pending":
×
1611
                query.Status = model.StatusQueryPending
×
1612
        case "aborted":
×
1613
                query.Status = model.StatusQueryAborted
×
1614
        case "":
3✔
1615
                query.Status = model.StatusQueryAny
3✔
1616
        default:
×
1617
                return query, errors.Errorf("unknown status %s", status)
×
1618

1619
        }
1620

1621
        dType := vals.Get("type")
3✔
1622
        if dType == "" {
6✔
1623
                return query, nil
3✔
1624
        }
3✔
1625
        deploymentType := model.DeploymentType(dType)
×
1626
        if deploymentType == model.DeploymentTypeSoftware ||
×
1627
                deploymentType == model.DeploymentTypeConfiguration {
×
1628
                query.Type = deploymentType
×
1629
        } else {
×
1630
                return query, errors.Errorf("unknown deployment type %s", dType)
×
1631
        }
×
1632

1633
        return query, nil
×
1634
}
1635

1636
func ParseDeploymentLookupQueryV1(vals url.Values) (model.Query, error) {
3✔
1637
        query, err := ParseLookupQuery(vals)
3✔
1638
        if err != nil {
4✔
1639
                return query, err
1✔
1640
        }
1✔
1641

1642
        search := vals.Get("search")
3✔
1643
        if search != "" {
3✔
1644
                query.SearchText = search
×
1645
        }
×
1646

1647
        return query, nil
3✔
1648
}
1649

1650
func ParseDeploymentLookupQueryV2(vals url.Values) (model.Query, error) {
2✔
1651
        query, err := ParseLookupQuery(vals)
2✔
1652
        if err != nil {
2✔
1653
                return query, err
×
1654
        }
×
1655

1656
        query.Names = vals["name"]
2✔
1657
        query.IDs = vals["id"]
2✔
1658

2✔
1659
        return query, nil
2✔
1660
}
1661

1662
func parseEpochToTimestamp(epoch string) (time.Time, error) {
2✔
1663
        if epochInt64, err := strconv.ParseInt(epoch, 10, 64); err != nil {
3✔
1664
                return time.Time{}, errors.New("invalid timestamp: " + epoch)
1✔
1665
        } else {
2✔
1666
                return time.Unix(epochInt64, 0).UTC(), nil
1✔
1667
        }
1✔
1668
}
1669

1670
func (d *DeploymentsApiHandlers) LookupDeployment(w rest.ResponseWriter, r *rest.Request) {
3✔
1671
        ctx := r.Context()
3✔
1672
        l := requestlog.GetRequestLogger(r)
3✔
1673
        q := r.URL.Query()
3✔
1674
        defer func() {
6✔
1675
                if search := q.Get("search"); search != "" {
3✔
1676
                        q.Set("search", Redacted)
×
1677
                        r.URL.RawQuery = q.Encode()
×
1678
                }
×
1679
        }()
1680

1681
        query, err := ParseDeploymentLookupQueryV1(q)
3✔
1682
        if err != nil {
4✔
1683
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
1✔
1684
                return
1✔
1685
        }
1✔
1686

1687
        page, perPage, err := rest_utils.ParsePagination(r)
3✔
1688
        if err != nil {
4✔
1689
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
1✔
1690
                return
1✔
1691
        }
1✔
1692
        query.Skip = int((page - 1) * perPage)
3✔
1693
        query.Limit = int(perPage + 1)
3✔
1694

3✔
1695
        deps, totalCount, err := d.app.LookupDeployment(ctx, query)
3✔
1696
        if err != nil {
4✔
1697
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
1✔
1698
                return
1✔
1699
        }
1✔
1700
        w.Header().Add(hdrTotalCount, strconv.FormatInt(totalCount, 10))
3✔
1701

3✔
1702
        len := len(deps)
3✔
1703
        hasNext := false
3✔
1704
        if uint64(len) > perPage {
3✔
1705
                hasNext = true
×
1706
                len = int(perPage)
×
1707
        }
×
1708

1709
        links := rest_utils.MakePageLinkHdrs(r, page, perPage, hasNext)
3✔
1710
        for _, l := range links {
6✔
1711
                w.Header().Add(hdrLink, l)
3✔
1712
        }
3✔
1713

1714
        d.view.RenderSuccessGet(w, deps[:len])
3✔
1715
}
1716

1717
func (d *DeploymentsApiHandlers) LookupDeploymentV2(w rest.ResponseWriter, r *rest.Request) {
2✔
1718
        ctx := r.Context()
2✔
1719
        l := requestlog.GetRequestLogger(r)
2✔
1720
        q := r.URL.Query()
2✔
1721
        defer func() {
4✔
1722
                if q.Has("name") {
3✔
1723
                        q["name"] = []string{Redacted}
1✔
1724
                        r.URL.RawQuery = q.Encode()
1✔
1725
                }
1✔
1726
        }()
1727

1728
        query, err := ParseDeploymentLookupQueryV2(q)
2✔
1729
        if err != nil {
2✔
1730
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
×
1731
                return
×
1732
        }
×
1733

1734
        page, perPage, err := rest_utils.ParsePagination(r)
2✔
1735
        if err != nil {
3✔
1736
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
1✔
1737
                return
1✔
1738
        }
1✔
1739
        query.Skip = int((page - 1) * perPage)
2✔
1740
        query.Limit = int(perPage + 1)
2✔
1741

2✔
1742
        deps, totalCount, err := d.app.LookupDeployment(ctx, query)
2✔
1743
        if err != nil {
2✔
1744
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
×
1745
                return
×
1746
        }
×
1747
        w.Header().Add(hdrTotalCount, strconv.FormatInt(totalCount, 10))
2✔
1748

2✔
1749
        len := len(deps)
2✔
1750
        hasNext := false
2✔
1751
        if uint64(len) > perPage {
3✔
1752
                hasNext = true
1✔
1753
                len = int(perPage)
1✔
1754
        }
1✔
1755

1756
        links := rest_utils.MakePageLinkHdrs(r, page, perPage, hasNext)
2✔
1757
        for _, l := range links {
4✔
1758
                w.Header().Add(hdrLink, l)
2✔
1759
        }
2✔
1760

1761
        d.view.RenderSuccessGet(w, deps[:len])
2✔
1762
}
1763

1764
func (d *DeploymentsApiHandlers) PutDeploymentLogForDevice(w rest.ResponseWriter, r *rest.Request) {
1✔
1765
        ctx := r.Context()
1✔
1766
        l := requestlog.GetRequestLogger(r)
1✔
1767

1✔
1768
        did := r.PathParam("id")
1✔
1769

1✔
1770
        idata := identity.FromContext(ctx)
1✔
1771
        if idata == nil {
1✔
1772
                d.view.RenderError(w, r, ErrMissingIdentity, http.StatusBadRequest, l)
×
1773
                return
×
1774
        }
×
1775

1776
        // reuse DeploymentLog, device and deployment IDs are ignored when
1777
        // (un-)marshaling DeploymentLog to/from JSON
1778
        var log model.DeploymentLog
1✔
1779

1✔
1780
        err := r.DecodeJsonPayload(&log)
1✔
1781
        if err != nil {
1✔
1782
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
×
1783
                return
×
1784
        }
×
1785

1786
        if err := d.app.SaveDeviceDeploymentLog(ctx, idata.Subject,
1✔
1787
                did, log.Messages); err != nil {
1✔
1788

×
1789
                if err == app.ErrModelDeploymentNotFound {
×
1790
                        d.view.RenderError(w, r, err, http.StatusNotFound, l)
×
1791
                } else {
×
1792
                        d.view.RenderInternalError(w, r, err, l)
×
1793
                }
×
1794
                return
×
1795
        }
1796

1797
        d.view.RenderEmptySuccessResponse(w)
1✔
1798
}
1799

1800
func (d *DeploymentsApiHandlers) GetDeploymentLogForDevice(w rest.ResponseWriter, r *rest.Request) {
1✔
1801
        ctx := r.Context()
1✔
1802
        l := requestlog.GetRequestLogger(r)
1✔
1803

1✔
1804
        did := r.PathParam("id")
1✔
1805
        devid := r.PathParam("devid")
1✔
1806

1✔
1807
        depl, err := d.app.GetDeviceDeploymentLog(ctx, devid, did)
1✔
1808

1✔
1809
        if err != nil {
1✔
1810
                d.view.RenderInternalError(w, r, err, l)
×
1811
                return
×
1812
        }
×
1813

1814
        if depl == nil {
1✔
1815
                d.view.RenderErrorNotFound(w, r, l)
×
1816
                return
×
1817
        }
×
1818

1819
        d.view.RenderDeploymentLog(w, *depl)
1✔
1820
}
1821

1822
func (d *DeploymentsApiHandlers) AbortDeviceDeployments(w rest.ResponseWriter, r *rest.Request) {
1✔
1823
        ctx := r.Context()
1✔
1824
        l := requestlog.GetRequestLogger(r)
1✔
1825

1✔
1826
        id := r.PathParam("id")
1✔
1827
        err := d.app.AbortDeviceDeployments(ctx, id)
1✔
1828

1✔
1829
        switch err {
1✔
1830
        case nil, app.ErrStorageNotFound:
1✔
1831
                d.view.RenderEmptySuccessResponse(w)
1✔
1832
        default:
1✔
1833
                d.view.RenderInternalError(w, r, err, l)
1✔
1834
        }
1835
}
1836

1837
func (d *DeploymentsApiHandlers) DeleteDeviceDeploymentsHistory(w rest.ResponseWriter,
1838
        r *rest.Request) {
1✔
1839
        ctx := r.Context()
1✔
1840
        l := requestlog.GetRequestLogger(r)
1✔
1841

1✔
1842
        id := r.PathParam("id")
1✔
1843
        err := d.app.DeleteDeviceDeploymentsHistory(ctx, id)
1✔
1844

1✔
1845
        switch err {
1✔
1846
        case nil, app.ErrStorageNotFound:
1✔
1847
                d.view.RenderEmptySuccessResponse(w)
1✔
1848
        default:
1✔
1849
                d.view.RenderInternalError(w, r, err, l)
1✔
1850
        }
1851
}
1852

1853
func (d *DeploymentsApiHandlers) ListDeviceDeployments(w rest.ResponseWriter, r *rest.Request) {
2✔
1854
        ctx := r.Context()
2✔
1855
        d.listDeviceDeployments(ctx, w, r, true)
2✔
1856
}
2✔
1857

1858
func (d *DeploymentsApiHandlers) ListDeviceDeploymentsInternal(w rest.ResponseWriter,
1859
        r *rest.Request) {
2✔
1860
        ctx := r.Context()
2✔
1861
        tenantID := r.PathParam("tenant")
2✔
1862
        if tenantID != "" {
4✔
1863
                ctx = identity.WithContext(r.Context(), &identity.Identity{
2✔
1864
                        Tenant:   tenantID,
2✔
1865
                        IsDevice: true,
2✔
1866
                })
2✔
1867
        }
2✔
1868
        d.listDeviceDeployments(ctx, w, r, true)
2✔
1869
}
1870

1871
func (d *DeploymentsApiHandlers) ListDeviceDeploymentsByIDsInternal(w rest.ResponseWriter,
1872
        r *rest.Request) {
2✔
1873
        ctx := r.Context()
2✔
1874
        tenantID := r.PathParam("tenant")
2✔
1875
        if tenantID != "" {
4✔
1876
                ctx = identity.WithContext(r.Context(), &identity.Identity{
2✔
1877
                        Tenant:   tenantID,
2✔
1878
                        IsDevice: true,
2✔
1879
                })
2✔
1880
        }
2✔
1881
        d.listDeviceDeployments(ctx, w, r, false)
2✔
1882
}
1883

1884
func (d *DeploymentsApiHandlers) listDeviceDeployments(ctx context.Context,
1885
        w rest.ResponseWriter, r *rest.Request, byDeviceID bool) {
2✔
1886
        l := requestlog.GetRequestLogger(r)
2✔
1887

2✔
1888
        did := ""
2✔
1889
        var IDs []string
2✔
1890
        if byDeviceID {
4✔
1891
                did = r.PathParam("id")
2✔
1892
        } else {
4✔
1893
                values := r.URL.Query()
2✔
1894
                if values.Has("id") && len(values["id"]) > 0 {
3✔
1895
                        IDs = values["id"]
1✔
1896
                } else {
3✔
1897
                        d.view.RenderError(w, r, ErrEmptyID, http.StatusBadRequest, l)
2✔
1898
                        return
2✔
1899
                }
2✔
1900
        }
1901

1902
        page, perPage, err := rest_utils.ParsePagination(r)
2✔
1903
        if err == nil && perPage > MaximumPerPageListDeviceDeployments {
3✔
1904
                err = errors.New(rest_utils.MsgQueryParmLimit(ParamPerPage))
1✔
1905
        }
1✔
1906
        if err != nil {
3✔
1907
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
1✔
1908
                return
1✔
1909
        }
1✔
1910

1911
        lq := store.ListQueryDeviceDeployments{
2✔
1912
                Skip:     int((page - 1) * perPage),
2✔
1913
                Limit:    int(perPage),
2✔
1914
                DeviceID: did,
2✔
1915
                IDs:      IDs,
2✔
1916
        }
2✔
1917
        if status := r.URL.Query().Get("status"); status != "" {
3✔
1918
                lq.Status = &status
1✔
1919
        }
1✔
1920
        if err = lq.Validate(); err != nil {
3✔
1921
                d.view.RenderError(w, r, err, http.StatusBadRequest, l)
1✔
1922
                return
1✔
1923
        }
1✔
1924

1925
        deps, totalCount, err := d.app.GetDeviceDeploymentListForDevice(ctx, lq)
2✔
1926
        if err != nil {
3✔
1927
                d.view.RenderInternalError(w, r, err, l)
1✔
1928
                return
1✔
1929
        }
1✔
1930
        w.Header().Add(hdrTotalCount, strconv.FormatInt(int64(totalCount), 10))
2✔
1931

2✔
1932
        hasNext := totalCount > lq.Skip+len(deps)
2✔
1933
        links := rest_utils.MakePageLinkHdrs(r, page, perPage, hasNext)
2✔
1934
        for _, l := range links {
4✔
1935
                w.Header().Add(hdrLink, l)
2✔
1936
        }
2✔
1937

1938
        d.view.RenderSuccessGet(w, deps)
2✔
1939
}
1940

1941
func (d *DeploymentsApiHandlers) AbortDeviceDeploymentsInternal(w rest.ResponseWriter,
1942
        r *rest.Request) {
1✔
1943
        ctx := r.Context()
1✔
1944
        tenantID := r.PathParam("tenantID")
1✔
1945
        if tenantID != "" {
1✔
1946
                ctx = identity.WithContext(r.Context(), &identity.Identity{
×
1947
                        Tenant:   tenantID,
×
1948
                        IsDevice: true,
×
1949
                })
×
1950
        }
×
1951

1952
        l := requestlog.GetRequestLogger(r)
1✔
1953

1✔
1954
        id := r.PathParam("id")
1✔
1955

1✔
1956
        // Decommission deployments for devices and update deployment stats
1✔
1957
        err := d.app.DecommissionDevice(ctx, id)
1✔
1958

1✔
1959
        switch err {
1✔
1960
        case nil, app.ErrStorageNotFound:
1✔
1961
                d.view.RenderEmptySuccessResponse(w)
1✔
1962
        default:
×
1963
                d.view.RenderInternalError(w, r, err, l)
×
1964

1965
        }
1966
}
1967

1968
// tenants
1969

1970
func (d *DeploymentsApiHandlers) ProvisionTenantsHandler(w rest.ResponseWriter, r *rest.Request) {
2✔
1971
        ctx := r.Context()
2✔
1972
        l := requestlog.GetRequestLogger(r)
2✔
1973

2✔
1974
        defer r.Body.Close()
2✔
1975

2✔
1976
        tenant, err := model.ParseNewTenantReq(r.Body)
2✔
1977
        if err != nil {
4✔
1978
                rest_utils.RestErrWithLog(w, r, l, err, http.StatusBadRequest)
2✔
1979
                return
2✔
1980
        }
2✔
1981

1982
        err = d.app.ProvisionTenant(ctx, tenant.TenantId)
1✔
1983
        if err != nil {
1✔
1984
                rest_utils.RestErrWithLogInternal(w, r, l, err)
×
1985
                return
×
1986
        }
×
1987

1988
        w.WriteHeader(http.StatusCreated)
1✔
1989
}
1990

1991
func (d *DeploymentsApiHandlers) DeploymentsPerTenantHandler(
1992
        w rest.ResponseWriter,
1993
        r *rest.Request,
1994
) {
2✔
1995
        tenantID := r.PathParam("tenant")
2✔
1996
        if tenantID == "" {
3✔
1997
                l := requestlog.GetRequestLogger(r)
1✔
1998
                rest_utils.RestErrWithLog(w, r, l, errors.New("missing tenant ID"), http.StatusBadRequest)
1✔
1999
                return
1✔
2000
        }
1✔
2001

2002
        r.Request = r.WithContext(identity.WithContext(
2✔
2003
                r.Context(),
2✔
2004
                &identity.Identity{Tenant: tenantID},
2✔
2005
        ))
2✔
2006
        d.LookupDeployment(w, r)
2✔
2007
}
2008

2009
func (d *DeploymentsApiHandlers) GetTenantStorageSettingsHandler(
2010
        w rest.ResponseWriter,
2011
        r *rest.Request,
2012
) {
3✔
2013
        l := requestlog.GetRequestLogger(r)
3✔
2014

3✔
2015
        tenantID := r.PathParam("tenant")
3✔
2016

3✔
2017
        ctx := identity.WithContext(
3✔
2018
                r.Context(),
3✔
2019
                &identity.Identity{Tenant: tenantID},
3✔
2020
        )
3✔
2021

3✔
2022
        settings, err := d.app.GetStorageSettings(ctx)
3✔
2023
        if err != nil {
4✔
2024
                rest_utils.RestErrWithLogInternal(w, r, l, err)
1✔
2025
                return
1✔
2026
        }
1✔
2027

2028
        d.view.RenderSuccessGet(w, settings)
3✔
2029
}
2030

2031
func (d *DeploymentsApiHandlers) PutTenantStorageSettingsHandler(
2032
        w rest.ResponseWriter,
2033
        r *rest.Request,
2034
) {
3✔
2035
        l := requestlog.GetRequestLogger(r)
3✔
2036

3✔
2037
        defer r.Body.Close()
3✔
2038

3✔
2039
        tenantID := r.PathParam("tenant")
3✔
2040

3✔
2041
        ctx := identity.WithContext(
3✔
2042
                r.Context(),
3✔
2043
                &identity.Identity{Tenant: tenantID},
3✔
2044
        )
3✔
2045

3✔
2046
        settings, err := model.ParseStorageSettingsRequest(r.Body)
3✔
2047
        if err != nil {
6✔
2048
                rest_utils.RestErrWithLog(w, r, l, err, http.StatusBadRequest)
3✔
2049
                return
3✔
2050
        }
3✔
2051

2052
        err = d.app.SetStorageSettings(ctx, settings)
2✔
2053
        if err != nil {
3✔
2054
                rest_utils.RestErrWithLogInternal(w, r, l, err)
1✔
2055
                return
1✔
2056
        }
1✔
2057

2058
        w.WriteHeader(http.StatusNoContent)
2✔
2059
}
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2025 Coveralls, Inc