woodpecker/server/remote/gitea/gitea.go

543 lines
15 KiB
Go
Raw Normal View History

// Copyright 2022 Woodpecker Authors
// Copyright 2021 Informatyka Boguslawski sp. z o.o. sp.k., http://www.ib.pl/
// Copyright 2018 Drone.IO Inc.
//
2018-02-19 22:24:10 +00:00
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
2018-02-19 22:24:10 +00:00
// http://www.apache.org/licenses/LICENSE-2.0
//
2018-02-19 22:24:10 +00:00
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
//
// This file has been modified by Informatyka Boguslawski sp. z o.o. sp.k.
2018-02-19 22:24:10 +00:00
2017-05-01 10:33:06 +00:00
package gitea
import (
"context"
2017-05-01 10:33:06 +00:00
"crypto/tls"
"fmt"
"net"
"net/http"
"net/url"
"path"
"path/filepath"
"strconv"
"strings"
"time"
2017-05-01 10:33:06 +00:00
2017-05-02 01:09:36 +00:00
"code.gitea.io/sdk/gitea"
"github.com/rs/zerolog/log"
"golang.org/x/oauth2"
"github.com/woodpecker-ci/woodpecker/server"
"github.com/woodpecker-ci/woodpecker/server/model"
"github.com/woodpecker-ci/woodpecker/server/remote"
"github.com/woodpecker-ci/woodpecker/server/remote/common"
)
const (
authorizeTokenURL = "%s/login/oauth/authorize"
accessTokenURL = "%s/login/oauth/access_token"
perPage = 50
giteaDevVersion = "v1.18.0"
2017-05-01 10:33:06 +00:00
)
type Gitea struct {
URL string
ClientID string
ClientSecret string
SkipVerify bool
}
2017-05-01 10:33:06 +00:00
// Opts defines configuration options.
type Opts struct {
URL string // Gitea server url.
Client string // OAuth2 Client ID
Secret string // OAuth2 Client Secret
SkipVerify bool // Skip ssl verification.
2017-05-01 10:33:06 +00:00
}
// New returns a Remote implementation that integrates with Gitea,
// an open source Git service written in Go. See https://gitea.io/
2017-05-01 10:33:06 +00:00
func New(opts Opts) (remote.Remote, error) {
u, err := url.Parse(opts.URL)
2017-05-01 10:33:06 +00:00
if err != nil {
return nil, err
}
host, _, err := net.SplitHostPort(u.Host)
2017-05-01 10:33:06 +00:00
if err == nil {
u.Host = host
2017-05-01 10:33:06 +00:00
}
return &Gitea{
URL: opts.URL,
ClientID: opts.Client,
ClientSecret: opts.Secret,
SkipVerify: opts.SkipVerify,
2017-05-01 10:33:06 +00:00
}, nil
}
2022-06-17 18:14:01 +00:00
// Name returns the string name of this driver
func (c *Gitea) Name() string {
return "gitea"
}
func (c *Gitea) oauth2Config(ctx context.Context) (*oauth2.Config, context.Context) {
return &oauth2.Config{
ClientID: c.ClientID,
ClientSecret: c.ClientSecret,
Endpoint: oauth2.Endpoint{
AuthURL: fmt.Sprintf(authorizeTokenURL, c.URL),
TokenURL: fmt.Sprintf(accessTokenURL, c.URL),
},
RedirectURL: fmt.Sprintf("%s/authorize", server.Config.Server.OAuthHost),
},
context.WithValue(ctx, oauth2.HTTPClient, &http.Client{Transport: &http.Transport{
TLSClientConfig: &tls.Config{InsecureSkipVerify: c.SkipVerify},
Proxy: http.ProxyFromEnvironment,
}})
}
// Login authenticates an account with Gitea using basic authentication. The
// Gitea account details are returned when the user is successfully authenticated.
func (c *Gitea) Login(ctx context.Context, w http.ResponseWriter, req *http.Request) (*model.User, error) {
config, oauth2Ctx := c.oauth2Config(ctx)
2017-05-01 10:33:06 +00:00
// get the OAuth errors
if err := req.FormValue("error"); err != "" {
return nil, &remote.AuthError{
Err: err,
Description: req.FormValue("error_description"),
URI: req.FormValue("error_uri"),
}
}
2017-05-01 10:33:06 +00:00
// get the OAuth code
code := req.FormValue("code")
if len(code) == 0 {
http.Redirect(w, req, config.AuthCodeURL("woodpecker"), http.StatusSeeOther)
return nil, nil
2017-05-01 10:33:06 +00:00
}
token, err := config.Exchange(oauth2Ctx, code)
if err != nil {
return nil, err
2017-05-01 10:33:06 +00:00
}
client, err := c.newClientToken(ctx, token.AccessToken)
if err != nil {
return nil, err
}
account, _, err := client.GetMyUserInfo()
2017-05-01 10:33:06 +00:00
if err != nil {
return nil, err
}
return &model.User{
Token: token.AccessToken,
Secret: token.RefreshToken,
Expiry: token.Expiry.UTC().Unix(),
2017-05-01 10:33:06 +00:00
Login: account.UserName,
Email: account.Email,
Avatar: expandAvatar(c.URL, account.AvatarURL),
}, nil
}
// Auth uses the Gitea oauth2 access token and refresh token to authenticate
// a session and return the Gitea account login.
func (c *Gitea) Auth(ctx context.Context, token, secret string) (string, error) {
client, err := c.newClientToken(ctx, token)
if err != nil {
return "", err
}
user, _, err := client.GetMyUserInfo()
if err != nil {
return "", err
}
return user.UserName, nil
}
// Refresh refreshes the Gitea oauth2 access token. If the token is
// refreshed the user is updated and a true value is returned.
func (c *Gitea) Refresh(ctx context.Context, user *model.User) (bool, error) {
config, oauth2Ctx := c.oauth2Config(ctx)
config.RedirectURL = ""
source := config.TokenSource(oauth2Ctx, &oauth2.Token{
AccessToken: user.Token,
RefreshToken: user.Secret,
Expiry: time.Unix(user.Expiry, 0),
})
token, err := source.Token()
if err != nil || len(token.AccessToken) == 0 {
return false, err
}
user.Token = token.AccessToken
user.Secret = token.RefreshToken
user.Expiry = token.Expiry.UTC().Unix()
return true, nil
2017-05-01 10:33:06 +00:00
}
2017-05-02 01:09:36 +00:00
// Teams is supported by the Gitea driver.
func (c *Gitea) Teams(ctx context.Context, u *model.User) ([]*model.Team, error) {
client, err := c.newClientToken(ctx, u.Token)
if err != nil {
return nil, err
}
return common.Paginate(func(page int) ([]*model.Team, error) {
orgs, _, err := client.ListMyOrgs(
gitea.ListOrgsOptions{
ListOptions: gitea.ListOptions{
Page: page,
PageSize: perPage,
},
},
)
teams := make([]*model.Team, 0, len(orgs))
for _, org := range orgs {
teams = append(teams, toTeam(org, c.URL))
}
return teams, err
})
2017-05-01 10:33:06 +00:00
}
// TeamPerm is not supported by the Gitea driver.
func (c *Gitea) TeamPerm(u *model.User, org string) (*model.Perm, error) {
2017-05-01 10:33:06 +00:00
return nil, nil
}
// Repo returns the Gitea repository.
func (c *Gitea) Repo(ctx context.Context, u *model.User, id model.RemoteID, owner, name string) (*model.Repo, error) {
client, err := c.newClientToken(ctx, u.Token)
if err != nil {
return nil, err
}
if id.IsValid() {
intID, err := strconv.ParseInt(string(id), 10, 64)
if err != nil {
return nil, err
}
repo, _, err := client.GetRepoByID(intID)
if err != nil {
return nil, err
}
return toRepo(repo), nil
}
repo, _, err := client.GetRepo(owner, name)
2017-05-01 10:33:06 +00:00
if err != nil {
return nil, err
}
return toRepo(repo), nil
2017-05-01 10:33:06 +00:00
}
// Repos returns a list of all repositories for the Gitea account, including
// organization repositories.
func (c *Gitea) Repos(ctx context.Context, u *model.User) ([]*model.Repo, error) {
client, err := c.newClientToken(ctx, u.Token)
if err != nil {
return nil, err
}
return common.Paginate(func(page int) ([]*model.Repo, error) {
repos, _, err := client.ListMyRepos(
gitea.ListReposOptions{
ListOptions: gitea.ListOptions{
Page: page,
PageSize: perPage,
},
},
)
result := make([]*model.Repo, 0, len(repos))
for _, repo := range repos {
result = append(result, toRepo(repo))
}
return result, err
})
2017-05-01 10:33:06 +00:00
}
// Perm returns the user permissions for the named Gitea repository.
func (c *Gitea) Perm(ctx context.Context, u *model.User, r *model.Repo) (*model.Perm, error) {
client, err := c.newClientToken(ctx, u.Token)
if err != nil {
return nil, err
}
repo, _, err := client.GetRepo(r.Owner, r.Name)
2017-05-01 10:33:06 +00:00
if err != nil {
return nil, err
}
return toPerm(repo.Permissions), nil
}
// File fetches the file from the Gitea repository and returns its contents.
func (c *Gitea) File(ctx context.Context, u *model.User, r *model.Repo, b *model.Pipeline, f string) ([]byte, error) {
client, err := c.newClientToken(ctx, u.Token)
if err != nil {
return nil, err
}
cfg, _, err := client.GetFile(r.Owner, r.Name, b.Commit, f)
2017-05-01 10:33:06 +00:00
return cfg, err
}
func (c *Gitea) Dir(ctx context.Context, u *model.User, r *model.Repo, b *model.Pipeline, f string) ([]*remote.FileMeta, error) {
var configs []*remote.FileMeta
client, err := c.newClientToken(ctx, u.Token)
if err != nil {
return nil, err
}
// List files in repository. Path from root
tree, _, err := client.GetTrees(r.Owner, r.Name, b.Commit, true)
if err != nil {
return nil, err
}
f = path.Clean(f) // We clean path and remove trailing slash
f += "/" + "*" // construct pattern for match i.e. file in subdir
for _, e := range tree.Entries {
// Filter path matching pattern and type file (blob)
if m, _ := filepath.Match(f, e.Path); m && e.Type == "blob" {
data, err := c.File(ctx, u, r, b, e.Path)
if err != nil {
return nil, fmt.Errorf("multi-pipeline cannot get %s: %s", e.Path, err)
}
configs = append(configs, &remote.FileMeta{
Name: e.Path,
Data: data,
})
}
}
return configs, nil
}
2017-05-02 01:09:36 +00:00
// Status is supported by the Gitea driver.
func (c *Gitea) Status(ctx context.Context, user *model.User, repo *model.Repo, pipeline *model.Pipeline, proc *model.Proc) error {
client, err := c.newClientToken(ctx, user.Token)
if err != nil {
return err
}
2017-05-01 10:33:06 +00:00
_, _, err = client.CreateStatus(
repo.Owner,
repo.Name,
pipeline.Commit,
2017-05-01 10:33:06 +00:00
gitea.CreateStatusOption{
State: getStatus(proc.State),
TargetURL: common.GetPipelineStatusLink(repo, pipeline, proc),
Description: common.GetPipelineStatusDescription(proc.State),
Context: common.GetPipelineStatusContext(repo, pipeline, proc),
2017-05-01 10:33:06 +00:00
},
)
2017-05-01 12:29:57 +00:00
return err
2017-05-01 10:33:06 +00:00
}
// Netrc returns a netrc file capable of authenticating Gitea requests and
// cloning Gitea repositories. The netrc will use the global machine account
// when configured.
func (c *Gitea) Netrc(u *model.User, r *model.Repo) (*model.Netrc, error) {
login := ""
token := ""
if u != nil {
login = u.Login
token = u.Token
2017-05-01 10:33:06 +00:00
}
host, err := common.ExtractHostFromCloneURL(r.Clone)
if err != nil {
return nil, err
}
2017-05-01 10:33:06 +00:00
return &model.Netrc{
Login: login,
Password: token,
Machine: host,
2017-05-01 10:33:06 +00:00
}, nil
}
// Activate activates the repository by registering post-commit hooks with
// the Gitea repository.
func (c *Gitea) Activate(ctx context.Context, u *model.User, r *model.Repo, link string) error {
2017-05-01 10:33:06 +00:00
config := map[string]string{
"url": link,
"secret": r.Hash,
"content_type": "json",
}
hook := gitea.CreateHookOption{
Type: gitea.HookTypeGitea,
2017-05-01 10:33:06 +00:00
Config: config,
Events: []string{"push", "create", "pull_request"},
Active: true,
}
client, err := c.newClientToken(ctx, u.Token)
if err != nil {
return err
}
_, response, err := client.CreateRepoHook(r.Owner, r.Name, hook)
if err != nil {
if response != nil {
if response.StatusCode == 404 {
return fmt.Errorf("Could not find repository")
}
if response.StatusCode == 200 {
return fmt.Errorf("Could not find repository, repository was probably renamed")
}
}
return err
}
return nil
2017-05-01 10:33:06 +00:00
}
// Deactivate deactives the repository be removing repository push hooks from
// the Gitea repository.
func (c *Gitea) Deactivate(ctx context.Context, u *model.User, r *model.Repo, link string) error {
client, err := c.newClientToken(ctx, u.Token)
if err != nil {
return err
}
hooks, _, err := client.ListRepoHooks(r.Owner, r.Name, gitea.ListHooksOptions{})
if err != nil {
return err
}
hook := matchingHooks(hooks, link)
if hook != nil {
_, err := client.DeleteRepoHook(r.Owner, r.Name, hook.ID)
return err
}
2017-05-01 10:33:06 +00:00
return nil
}
// Branches returns the names of all branches for the named repository.
func (c *Gitea) Branches(ctx context.Context, u *model.User, r *model.Repo) ([]string, error) {
token := ""
if u != nil {
token = u.Token
}
client, err := c.newClientToken(ctx, token)
if err != nil {
return nil, err
}
branches, err := common.Paginate(func(page int) ([]string, error) {
branches, _, err := client.ListRepoBranches(r.Owner, r.Name,
gitea.ListRepoBranchesOptions{ListOptions: gitea.ListOptions{Page: page}})
Fix branch loading (#1249) Fixes a panic I got while viewing the branches in the UI. ``` runtime error: index out of range [0] with length 0 /home/gitpod/go/src/runtime/panic.go:113 (0x44053e) goPanicIndex: panic(boundsError{x: int64(x), signed: true, y: y, code: boundsIndex}) /workspace/woodpecker/server/remote/gitea/gitea.go:444 (0xd36764) (*Gitea).Branches.func1: result[i] = branches[i].Name /workspace/woodpecker/server/remote/common/utils.go:34 (0xd3942a) Paginate[...]: batch, err := get(page) /workspace/woodpecker/server/remote/gitea/gitea.go:439 (0xd36665) (*Gitea).Branches: branches, err := common.Paginate(func(page int) ([]string, error) { /workspace/woodpecker/server/api/repo.go:202 (0xc823a1) GetRepoBranches: branches, err := r.Branches(c, user, repo) /workspace/go/pkg/mod/github.com/gin-gonic/gin@v1.8.1/context.go:173 (0xc71d44) (*Context).Next: c.handlers[c.index](c) /workspace/woodpecker/server/router/middleware/session/repo.go:148 (0xc71bba) MustPull: c.Next() /workspace/go/pkg/mod/github.com/gin-gonic/gin@v1.8.1/context.go:173 (0xc71aee) (*Context).Next: c.handlers[c.index](c) /workspace/woodpecker/server/router/middleware/session/repo.go:139 (0xc71aaa) SetPerm.func1: c.Next() /workspace/go/pkg/mod/github.com/gin-gonic/gin@v1.8.1/context.go:173 (0xc71251) (*Context).Next: c.handlers[c.index](c) /workspace/woodpecker/server/router/middleware/session/repo.go:53 (0xc710ec) SetRepo.func1: c.Next() /workspace/go/pkg/mod/github.com/gin-gonic/gin@v1.8.1/context.go:173 (0xccb50f) (*Context).Next: c.handlers[c.index](c) /workspace/woodpecker/server/router/middleware/token/token.go:50 (0xccb248) Refresh: c.Next() /workspace/go/pkg/mod/github.com/gin-gonic/gin@v1.8.1/context.go:173 (0xc721fc) (*Context).Next: c.handlers[c.index](c) /workspace/woodpecker/server/router/middleware/session/user.go:72 (0xc721e3) SetUser.func1: c.Next() /workspace/go/pkg/mod/github.com/gin-gonic/gin@v1.8.1/context.go:173 (0xcd069e) (*Context).Next: c.handlers[c.index](c) /workspace/woodpecker/server/router/middleware/store.go:29 (0xcd0685) Store.func1: c.Next() /workspace/go/pkg/mod/github.com/gin-gonic/gin@v1.8.1/context.go:173 (0xccff47) (*Context).Next: c.handlers[c.index](c) /workspace/woodpecker/server/router/middleware/logger.go:23 (0xccff2a) Logger.func1: c.Next() /workspace/go/pkg/mod/github.com/gin-gonic/gin@v1.8.1/context.go:173 (0xccaf99) (*Context).Next: c.handlers[c.index](c) /workspace/woodpecker/server/router/middleware/header/header.go:38 (0xccaec4) Options: c.Next() /workspace/go/pkg/mod/github.com/gin-gonic/gin@v1.8.1/context.go:173 (0xccae21) (*Context).Next: c.handlers[c.index](c) /workspace/woodpecker/server/router/middleware/header/header.go:30 (0xccae06) NoCache: c.Next() /workspace/go/pkg/mod/github.com/gin-gonic/gin@v1.8.1/context.go:173 (0xccf32a) (*Context).Next: c.handlers[c.index](c) /workspace/woodpecker/server/router/router.go:39 (0xccf310) Load.func1: c.Next() /workspace/go/pkg/mod/github.com/gin-gonic/gin@v1.8.1/context.go:173 (0xa2e0c1) (*Context).Next: c.handlers[c.index](c) /workspace/go/pkg/mod/github.com/gin-gonic/gin@v1.8.1/recovery.go:101 (0xa2e0ac) CustomRecoveryWithWriter.func1: c.Next() /workspace/go/pkg/mod/github.com/gin-gonic/gin@v1.8.1/context.go:173 (0xa2cf30) (*Context).Next: c.handlers[c.index](c) /workspace/go/pkg/mod/github.com/gin-gonic/gin@v1.8.1/gin.go:616 (0xa2cb98) (*Engine).handleHTTPRequest: c.Next() /workspace/go/pkg/mod/github.com/gin-gonic/gin@v1.8.1/gin.go:572 (0xa2c6dc) (*Engine).ServeHTTP: engine.handleHTTPRequest(c) /home/gitpod/go/src/net/http/server.go:2947 (0x79cc4b) serverHandler.ServeHTTP: handler.ServeHTTP(rw, req) /home/gitpod/go/src/net/http/server.go:1991 (0x797e66) (*conn).serve: serverHandler{c.server}.ServeHTTP(w, w.req) /home/gitpod/go/src/runtime/asm_amd64.s:1594 (0x476d80) goexit: BYTE $0x90 // NOP ``` Co-authored-by: Anbraten <anton@ju60.de>
2022-10-09 19:10:36 +00:00
result := make([]string, len(branches))
for i := range branches {
result[i] = branches[i].Name
}
return result, err
})
if err != nil {
return nil, err
}
return branches, nil
}
// BranchHead returns the sha of the head (lastest commit) of the specified branch
func (c *Gitea) BranchHead(ctx context.Context, u *model.User, r *model.Repo, branch string) (string, error) {
token := ""
if u != nil {
token = u.Token
}
client, err := c.newClientToken(ctx, token)
if err != nil {
return "", err
}
b, _, err := client.GetRepoBranch(r.Owner, r.Name, branch)
if err != nil {
return "", err
}
return b.Commit.ID, nil
}
// Hook parses the incoming Gitea hook and returns the Repository and Pipeline
2017-05-01 10:33:06 +00:00
// details. If the hook is unsupported nil values are returned.
func (c *Gitea) Hook(ctx context.Context, r *http.Request) (*model.Repo, *model.Pipeline, error) {
2017-05-01 10:33:06 +00:00
return parseHook(r)
}
// OrgMembership returns if user is member of organization and if user
// is admin/owner in this organization.
func (c *Gitea) OrgMembership(ctx context.Context, u *model.User, owner string) (*model.OrgPerm, error) {
client, err := c.newClientToken(ctx, u.Token)
if err != nil {
return nil, err
}
member, _, err := client.CheckOrgMembership(owner, u.Login)
if err != nil {
return nil, err
}
if !member {
return &model.OrgPerm{}, nil
}
perm, _, err := client.GetOrgPermissions(owner, u.Login)
if err != nil {
return &model.OrgPerm{Member: member}, err
}
return &model.OrgPerm{Member: member, Admin: perm.IsAdmin || perm.IsOwner}, nil
}
// helper function to return the Gitea client with Token
func (c *Gitea) newClientToken(ctx context.Context, token string) (*gitea.Client, error) {
httpClient := &http.Client{}
2017-05-01 10:33:06 +00:00
if c.SkipVerify {
httpClient.Transport = &http.Transport{
TLSClientConfig: &tls.Config{InsecureSkipVerify: true},
}
}
client, err := gitea.NewClient(c.URL, gitea.SetToken(token), gitea.SetHTTPClient(httpClient), gitea.SetContext(ctx))
if err != nil && strings.Contains(err.Error(), "Malformed version") {
// we guess it's a dev gitea version
log.Error().Err(err).Msgf("could not detect gitea version, assume dev version %s", giteaDevVersion)
client, err = gitea.NewClient(c.URL, gitea.SetGiteaVersion(giteaDevVersion), gitea.SetToken(token), gitea.SetHTTPClient(httpClient), gitea.SetContext(ctx))
}
return client, err
2017-05-01 10:33:06 +00:00
}
// getStatus is a helper function that converts a Woodpecker
// status to a Gitea status.
func getStatus(status model.StatusValue) gitea.StatusState {
switch status {
case model.StatusPending, model.StatusBlocked:
return gitea.StatusPending
case model.StatusRunning:
return gitea.StatusPending
case model.StatusSuccess:
return gitea.StatusSuccess
case model.StatusFailure, model.StatusError:
return gitea.StatusFailure
case model.StatusKilled:
return gitea.StatusFailure
case model.StatusDeclined:
return gitea.StatusWarning
default:
return gitea.StatusFailure
}
}