hosts.go 35 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147
  1. package controller
  2. import (
  3. "encoding/json"
  4. "errors"
  5. "fmt"
  6. "net/http"
  7. "time"
  8. "github.com/google/uuid"
  9. "github.com/gorilla/mux"
  10. "github.com/gravitl/netmaker/database"
  11. "github.com/gravitl/netmaker/logger"
  12. "github.com/gravitl/netmaker/logic"
  13. "github.com/gravitl/netmaker/models"
  14. "github.com/gravitl/netmaker/mq"
  15. "github.com/gravitl/netmaker/servercfg"
  16. "golang.org/x/crypto/bcrypt"
  17. "golang.org/x/exp/slog"
  18. )
  19. func hostHandlers(r *mux.Router) {
  20. r.HandleFunc("/api/hosts", logic.SecurityCheck(true, http.HandlerFunc(getHosts))).
  21. Methods(http.MethodGet)
  22. r.HandleFunc("/api/hosts/keys", logic.SecurityCheck(true, http.HandlerFunc(updateAllKeys))).
  23. Methods(http.MethodPut)
  24. r.HandleFunc("/api/hosts/sync", logic.SecurityCheck(true, http.HandlerFunc(syncHosts))).
  25. Methods(http.MethodPost)
  26. r.HandleFunc("/api/hosts/upgrade", logic.SecurityCheck(true, http.HandlerFunc(upgradeHosts))).
  27. Methods(http.MethodPost)
  28. r.HandleFunc("/api/hosts/{hostid}/keys", logic.SecurityCheck(true, http.HandlerFunc(updateKeys))).
  29. Methods(http.MethodPut)
  30. r.HandleFunc("/api/hosts/{hostid}/sync", logic.SecurityCheck(true, http.HandlerFunc(syncHost))).
  31. Methods(http.MethodPost)
  32. r.HandleFunc("/api/hosts/{hostid}", logic.SecurityCheck(true, http.HandlerFunc(updateHost))).
  33. Methods(http.MethodPut)
  34. r.HandleFunc("/api/hosts/{hostid}", Authorize(true, false, "all", http.HandlerFunc(deleteHost))).
  35. Methods(http.MethodDelete)
  36. r.HandleFunc("/api/hosts/{hostid}/upgrade", logic.SecurityCheck(true, http.HandlerFunc(upgradeHost))).
  37. Methods(http.MethodPut)
  38. r.HandleFunc("/api/hosts/{hostid}/networks/{network}", logic.SecurityCheck(true, http.HandlerFunc(addHostToNetwork))).
  39. Methods(http.MethodPost)
  40. r.HandleFunc("/api/hosts/{hostid}/networks/{network}", logic.SecurityCheck(true, http.HandlerFunc(deleteHostFromNetwork))).
  41. Methods(http.MethodDelete)
  42. r.HandleFunc("/api/hosts/adm/authenticate", authenticateHost).Methods(http.MethodPost)
  43. r.HandleFunc("/api/v1/host", Authorize(true, false, "host", http.HandlerFunc(pull))).
  44. Methods(http.MethodGet)
  45. r.HandleFunc("/api/v1/host/{hostid}/signalpeer", Authorize(true, false, "host", http.HandlerFunc(signalPeer))).
  46. Methods(http.MethodPost)
  47. r.HandleFunc("/api/v1/fallback/host/{hostid}", Authorize(true, false, "host", http.HandlerFunc(hostUpdateFallback))).
  48. Methods(http.MethodPut)
  49. r.HandleFunc("/api/v1/host/{hostid}/peer_info", Authorize(true, false, "host", http.HandlerFunc(getHostPeerInfo))).
  50. Methods(http.MethodGet)
  51. r.HandleFunc("/api/emqx/hosts", logic.SecurityCheck(true, http.HandlerFunc(delEmqxHosts))).
  52. Methods(http.MethodDelete)
  53. r.HandleFunc("/api/v1/auth-register/host", socketHandler)
  54. }
  55. // @Summary Requests all the hosts to upgrade their version
  56. // @Router /api/hosts/upgrade [post]
  57. // @Tags Hosts
  58. // @Security oauth
  59. // @Param force query bool false "Force upgrade"
  60. // @Success 200 {string} string "upgrade all hosts request received"
  61. func upgradeHosts(w http.ResponseWriter, r *http.Request) {
  62. w.Header().Set("Content-Type", "application/json")
  63. action := models.Upgrade
  64. if r.URL.Query().Get("force") == "true" {
  65. action = models.ForceUpgrade
  66. }
  67. user := r.Header.Get("user")
  68. go func() {
  69. slog.Info("requesting all hosts to upgrade", "user", user)
  70. hosts, err := logic.GetAllHosts()
  71. if err != nil {
  72. slog.Error("failed to retrieve all hosts", "user", user, "error", err)
  73. return
  74. }
  75. for _, host := range hosts {
  76. go func(host models.Host) {
  77. hostUpdate := models.HostUpdate{
  78. Action: action,
  79. Host: host,
  80. }
  81. if err = mq.HostUpdate(&hostUpdate); err != nil {
  82. slog.Error("failed to request host to upgrade", "user", user, "host", host.ID.String(), "error", err)
  83. } else {
  84. slog.Info("host upgrade requested", "user", user, "host", host.ID.String())
  85. }
  86. }(host)
  87. }
  88. }()
  89. logic.LogEvent(&models.Event{
  90. Action: models.UpgradeAll,
  91. Source: models.Subject{
  92. ID: r.Header.Get("user"),
  93. Name: r.Header.Get("user"),
  94. Type: models.UserSub,
  95. },
  96. TriggeredBy: r.Header.Get("user"),
  97. Target: models.Subject{
  98. ID: "All Hosts",
  99. Name: "All Hosts",
  100. Type: models.DeviceSub,
  101. },
  102. Origin: models.Dashboard,
  103. })
  104. slog.Info("upgrade all hosts request received", "user", user)
  105. logic.ReturnSuccessResponse(w, r, "upgrade all hosts request received")
  106. }
  107. // @Summary Upgrade a host
  108. // @Router /api/hosts/{hostid}/upgrade [put]
  109. // @Tags Hosts
  110. // @Security oauth
  111. // @Param hostid path string true "Host ID"
  112. // @Param force query bool false "Force upgrade"
  113. // @Success 200 {string} string "passed message to upgrade host"
  114. // @Failure 500 {object} models.ErrorResponse
  115. // upgrade host is a handler to send upgrade message to a host
  116. func upgradeHost(w http.ResponseWriter, r *http.Request) {
  117. host, err := logic.GetHost(mux.Vars(r)["hostid"])
  118. if err != nil {
  119. slog.Error("failed to find host", "error", err)
  120. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "notfound"))
  121. return
  122. }
  123. action := models.Upgrade
  124. if r.URL.Query().Get("force") == "true" {
  125. action = models.ForceUpgrade
  126. }
  127. if err := mq.HostUpdate(&models.HostUpdate{Action: action, Host: *host}); err != nil {
  128. slog.Error("failed to upgrade host", "error", err)
  129. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  130. return
  131. }
  132. logic.ReturnSuccessResponse(w, r, "passed message to upgrade host")
  133. }
  134. // @Summary List all hosts
  135. // @Router /api/hosts [get]
  136. // @Tags Hosts
  137. // @Security oauth
  138. // @Success 200 {array} models.ApiHost
  139. // @Failure 500 {object} models.ErrorResponse
  140. func getHosts(w http.ResponseWriter, r *http.Request) {
  141. w.Header().Set("Content-Type", "application/json")
  142. currentHosts, err := logic.GetAllHosts()
  143. if err != nil {
  144. logger.Log(0, r.Header.Get("user"), "failed to fetch hosts: ", err.Error())
  145. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  146. return
  147. }
  148. apiHosts := logic.GetAllHostsAPI(currentHosts[:])
  149. logger.Log(2, r.Header.Get("user"), "fetched all hosts")
  150. logic.SortApiHosts(apiHosts[:])
  151. w.WriteHeader(http.StatusOK)
  152. json.NewEncoder(w).Encode(apiHosts)
  153. }
  154. // @Summary Used by clients for "pull" command
  155. // @Router /api/v1/host [get]
  156. // @Tags Hosts
  157. // @Security oauth
  158. // @Success 200 {object} models.HostPull
  159. // @Failure 500 {object} models.ErrorResponse
  160. func pull(w http.ResponseWriter, r *http.Request) {
  161. hostID := r.Header.Get(hostIDHeader) // return JSON/API formatted keys
  162. if len(hostID) == 0 {
  163. logger.Log(0, "no host authorized to pull")
  164. logic.ReturnErrorResponse(
  165. w,
  166. r,
  167. logic.FormatError(fmt.Errorf("no host authorized to pull"), "internal"),
  168. )
  169. return
  170. }
  171. host, err := logic.GetHost(hostID)
  172. if err != nil {
  173. logger.Log(0, "no host found during pull", hostID)
  174. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  175. return
  176. }
  177. sendPeerUpdate := false
  178. for _, nodeID := range host.Nodes {
  179. node, err := logic.GetNodeByID(nodeID)
  180. if err != nil {
  181. slog.Error("failed to get node:", "id", node.ID, "error", err)
  182. continue
  183. }
  184. if node.FailedOverBy != uuid.Nil && r.URL.Query().Get("reset_failovered") == "true" {
  185. logic.ResetFailedOverPeer(&node)
  186. sendPeerUpdate = true
  187. }
  188. }
  189. if sendPeerUpdate {
  190. if err := mq.PublishPeerUpdate(false); err != nil {
  191. logger.Log(0, "fail to publish peer update: ", err.Error())
  192. }
  193. }
  194. allNodes, err := logic.GetAllNodes()
  195. if err != nil {
  196. logger.Log(0, "failed to get nodes: ", hostID)
  197. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  198. return
  199. }
  200. hPU, err := logic.GetPeerUpdateForHost("", host, allNodes, nil, nil)
  201. if err != nil {
  202. logger.Log(0, "could not pull peers for host", hostID, err.Error())
  203. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  204. return
  205. }
  206. serverConf := logic.GetServerInfo()
  207. key, keyErr := logic.RetrievePublicTrafficKey()
  208. if keyErr != nil {
  209. logger.Log(0, "error retrieving key:", keyErr.Error())
  210. logic.ReturnErrorResponse(w, r, logic.FormatError(keyErr, "internal"))
  211. return
  212. }
  213. _ = logic.CheckHostPorts(host)
  214. serverConf.TrafficKey = key
  215. response := models.HostPull{
  216. Host: *host,
  217. Nodes: logic.GetHostNodes(host),
  218. ServerConfig: serverConf,
  219. Peers: hPU.Peers,
  220. PeerIDs: hPU.PeerIDs,
  221. HostNetworkInfo: hPU.HostNetworkInfo,
  222. EgressRoutes: hPU.EgressRoutes,
  223. FwUpdate: hPU.FwUpdate,
  224. ChangeDefaultGw: hPU.ChangeDefaultGw,
  225. DefaultGwIp: hPU.DefaultGwIp,
  226. IsInternetGw: hPU.IsInternetGw,
  227. EndpointDetection: logic.IsEndpointDetectionEnabled(),
  228. DnsNameservers: hPU.DnsNameservers,
  229. }
  230. logger.Log(1, hostID, "completed a pull")
  231. w.WriteHeader(http.StatusOK)
  232. json.NewEncoder(w).Encode(&response)
  233. }
  234. // @Summary Updates a Netclient host on Netmaker server
  235. // @Router /api/hosts/{hostid} [put]
  236. // @Tags Hosts
  237. // @Security oauth
  238. // @Param hostid path string true "Host ID"
  239. // @Param body body models.ApiHost true "New host data"
  240. // @Success 200 {object} models.ApiHost
  241. // @Failure 500 {object} models.ErrorResponse
  242. func updateHost(w http.ResponseWriter, r *http.Request) {
  243. var newHostData models.ApiHost
  244. err := json.NewDecoder(r.Body).Decode(&newHostData)
  245. if err != nil {
  246. logger.Log(0, r.Header.Get("user"), "failed to update a host:", err.Error())
  247. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  248. return
  249. }
  250. // confirm host exists
  251. currHost, err := logic.GetHost(newHostData.ID)
  252. if err != nil {
  253. logger.Log(0, r.Header.Get("user"), "failed to update a host:", err.Error())
  254. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  255. return
  256. }
  257. newHost := newHostData.ConvertAPIHostToNMHost(currHost)
  258. logic.UpdateHost(newHost, currHost) // update the in memory struct values
  259. if err = logic.UpsertHost(newHost); err != nil {
  260. logger.Log(0, r.Header.Get("user"), "failed to update a host:", err.Error())
  261. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  262. return
  263. }
  264. // publish host update through MQ
  265. if err := mq.HostUpdate(&models.HostUpdate{
  266. Action: models.UpdateHost,
  267. Host: *newHost,
  268. }); err != nil {
  269. logger.Log(
  270. 0,
  271. r.Header.Get("user"),
  272. "failed to send host update: ",
  273. currHost.ID.String(),
  274. err.Error(),
  275. )
  276. }
  277. go func() {
  278. if err := mq.PublishPeerUpdate(false); err != nil {
  279. logger.Log(0, "fail to publish peer update: ", err.Error())
  280. }
  281. if newHost.Name != currHost.Name {
  282. if servercfg.IsDNSMode() {
  283. logic.SetDNS()
  284. }
  285. }
  286. }()
  287. logic.LogEvent(&models.Event{
  288. Action: models.Update,
  289. Source: models.Subject{
  290. ID: r.Header.Get("user"),
  291. Name: r.Header.Get("user"),
  292. Type: models.UserSub,
  293. },
  294. TriggeredBy: r.Header.Get("user"),
  295. Target: models.Subject{
  296. ID: currHost.ID.String(),
  297. Name: newHost.Name,
  298. Type: models.DeviceSub,
  299. },
  300. Diff: models.Diff{
  301. Old: currHost,
  302. New: newHost,
  303. },
  304. Origin: models.Dashboard,
  305. })
  306. apiHostData := newHost.ConvertNMHostToAPI()
  307. logger.Log(2, r.Header.Get("user"), "updated host", newHost.ID.String())
  308. w.WriteHeader(http.StatusOK)
  309. json.NewEncoder(w).Encode(apiHostData)
  310. }
  311. // @Summary Updates a Netclient host on Netmaker server
  312. // @Router /api/v1/fallback/host/{hostid} [put]
  313. // @Tags Hosts
  314. // @Security oauth
  315. // @Param hostid path string true "Host ID"
  316. // @Param body body models.HostUpdate true "Host update data"
  317. // @Success 200 {string} string "updated host data"
  318. // @Failure 500 {object} models.ErrorResponse
  319. func hostUpdateFallback(w http.ResponseWriter, r *http.Request) {
  320. var params = mux.Vars(r)
  321. hostid := params["hostid"]
  322. currentHost, err := logic.GetHost(hostid)
  323. if err != nil {
  324. slog.Error("error getting host", "id", hostid, "error", err)
  325. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "badrequest"))
  326. return
  327. }
  328. var sendPeerUpdate bool
  329. var replacePeers bool
  330. var hostUpdate models.HostUpdate
  331. err = json.NewDecoder(r.Body).Decode(&hostUpdate)
  332. if err != nil {
  333. slog.Error("failed to update a host:", "user", r.Header.Get("user"), "error", err.Error(), "host", currentHost.Name)
  334. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  335. return
  336. }
  337. slog.Info("recieved host update", "name", hostUpdate.Host.Name, "id", hostUpdate.Host.ID, "action", hostUpdate.Action)
  338. switch hostUpdate.Action {
  339. case models.CheckIn:
  340. sendPeerUpdate = mq.HandleHostCheckin(&hostUpdate.Host, currentHost)
  341. case models.UpdateHost:
  342. if hostUpdate.Host.PublicKey != currentHost.PublicKey {
  343. //remove old peer entry
  344. replacePeers = true
  345. }
  346. sendPeerUpdate = logic.UpdateHostFromClient(&hostUpdate.Host, currentHost)
  347. err := logic.UpsertHost(currentHost)
  348. if err != nil {
  349. slog.Error("failed to update host", "id", currentHost.ID, "error", err)
  350. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  351. return
  352. }
  353. case models.UpdateMetrics:
  354. mq.UpdateMetricsFallBack(hostUpdate.Node.ID.String(), hostUpdate.NewMetrics)
  355. }
  356. if sendPeerUpdate {
  357. err := mq.PublishPeerUpdate(replacePeers)
  358. if err != nil {
  359. slog.Error("failed to publish peer update", "error", err)
  360. }
  361. }
  362. logic.ReturnSuccessResponse(w, r, "updated host data")
  363. }
  364. // @Summary Deletes a Netclient host from Netmaker server
  365. // @Router /api/hosts/{hostid} [delete]
  366. // @Tags Hosts
  367. // @Security oauth
  368. // @Param hostid path string true "Host ID"
  369. // @Param force query bool false "Force delete"
  370. // @Success 200 {object} models.ApiHost
  371. // @Failure 500 {object} models.ErrorResponse
  372. func deleteHost(w http.ResponseWriter, r *http.Request) {
  373. var params = mux.Vars(r)
  374. hostid := params["hostid"]
  375. forceDelete := r.URL.Query().Get("force") == "true"
  376. // confirm host exists
  377. currHost, err := logic.GetHost(hostid)
  378. if err != nil {
  379. logger.Log(0, r.Header.Get("user"), "failed to delete a host:", err.Error())
  380. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  381. return
  382. }
  383. for _, nodeID := range currHost.Nodes {
  384. node, err := logic.GetNodeByID(nodeID)
  385. if err != nil {
  386. slog.Error("failed to get node", "nodeid", nodeID, "error", err)
  387. continue
  388. }
  389. var gwClients []models.ExtClient
  390. if node.IsIngressGateway {
  391. gwClients = logic.GetGwExtclients(node.ID.String(), node.Network)
  392. }
  393. go mq.PublishMqUpdatesForDeletedNode(node, false, gwClients)
  394. }
  395. if servercfg.GetBrokerType() == servercfg.EmqxBrokerType {
  396. // delete EMQX credentials for host
  397. if err := mq.GetEmqxHandler().DeleteEmqxUser(currHost.ID.String()); err != nil {
  398. slog.Error(
  399. "failed to remove host credentials from EMQX",
  400. "id",
  401. currHost.ID,
  402. "error",
  403. err,
  404. )
  405. }
  406. }
  407. if err = mq.HostUpdate(&models.HostUpdate{
  408. Action: models.DeleteHost,
  409. Host: *currHost,
  410. }); err != nil {
  411. logger.Log(
  412. 0,
  413. r.Header.Get("user"),
  414. "failed to send delete host update: ",
  415. currHost.ID.String(),
  416. err.Error(),
  417. )
  418. }
  419. if err = logic.RemoveHost(currHost, forceDelete); err != nil {
  420. logger.Log(0, r.Header.Get("user"), "failed to delete a host:", err.Error())
  421. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  422. return
  423. }
  424. logic.LogEvent(&models.Event{
  425. Action: models.Delete,
  426. Source: models.Subject{
  427. ID: r.Header.Get("user"),
  428. Name: r.Header.Get("user"),
  429. Type: models.UserSub,
  430. },
  431. TriggeredBy: r.Header.Get("user"),
  432. Target: models.Subject{
  433. ID: currHost.ID.String(),
  434. Name: currHost.Name,
  435. Type: models.DeviceSub,
  436. },
  437. Origin: models.Dashboard,
  438. })
  439. apiHostData := currHost.ConvertNMHostToAPI()
  440. logger.Log(2, r.Header.Get("user"), "removed host", currHost.Name)
  441. w.WriteHeader(http.StatusOK)
  442. json.NewEncoder(w).Encode(apiHostData)
  443. }
  444. // @Summary To Add Host To Network
  445. // @Router /api/hosts/{hostid}/networks/{network} [post]
  446. // @Tags Hosts
  447. // @Security oauth
  448. // @Param hostid path string true "Host ID"
  449. // @Param network path string true "Network name"
  450. // @Success 200 {string} string "OK"
  451. // @Failure 500 {object} models.ErrorResponse
  452. func addHostToNetwork(w http.ResponseWriter, r *http.Request) {
  453. var params = mux.Vars(r)
  454. hostid := params["hostid"]
  455. network := params["network"]
  456. if hostid == "" || network == "" {
  457. logic.ReturnErrorResponse(
  458. w,
  459. r,
  460. logic.FormatError(errors.New("hostid or network cannot be empty"), "badrequest"),
  461. )
  462. return
  463. }
  464. // confirm host exists
  465. currHost, err := logic.GetHost(hostid)
  466. if err != nil {
  467. logger.Log(0, r.Header.Get("user"), "failed to find host:", hostid, err.Error())
  468. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  469. return
  470. }
  471. newNode, err := logic.UpdateHostNetwork(currHost, network, true)
  472. if err != nil {
  473. logger.Log(
  474. 0,
  475. r.Header.Get("user"),
  476. "failed to add host to network:",
  477. hostid,
  478. network,
  479. err.Error(),
  480. )
  481. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  482. return
  483. }
  484. logger.Log(1, "added new node", newNode.ID.String(), "to host", currHost.Name)
  485. if currHost.IsDefault {
  486. // make host failover
  487. logic.CreateFailOver(*newNode)
  488. // make host remote access gateway
  489. logic.CreateIngressGateway(network, newNode.ID.String(), models.IngressRequest{})
  490. logic.CreateRelay(models.RelayRequest{
  491. NodeID: newNode.ID.String(),
  492. NetID: network,
  493. })
  494. }
  495. go func() {
  496. mq.HostUpdate(&models.HostUpdate{
  497. Action: models.JoinHostToNetwork,
  498. Host: *currHost,
  499. Node: *newNode,
  500. })
  501. mq.PublishPeerUpdate(false)
  502. if servercfg.IsDNSMode() {
  503. logic.SetDNS()
  504. }
  505. }()
  506. logger.Log(
  507. 2,
  508. r.Header.Get("user"),
  509. fmt.Sprintf("added host %s to network %s", currHost.Name, network),
  510. )
  511. logic.LogEvent(&models.Event{
  512. Action: models.JoinHostToNet,
  513. Source: models.Subject{
  514. ID: r.Header.Get("user"),
  515. Name: r.Header.Get("user"),
  516. Type: models.UserSub,
  517. },
  518. TriggeredBy: r.Header.Get("user"),
  519. Target: models.Subject{
  520. ID: currHost.ID.String(),
  521. Name: currHost.Name,
  522. Type: models.DeviceSub,
  523. },
  524. NetworkID: models.NetworkID(network),
  525. Origin: models.Dashboard,
  526. })
  527. w.WriteHeader(http.StatusOK)
  528. }
  529. // @Summary To Remove Host from Network
  530. // @Router /api/hosts/{hostid}/networks/{network} [delete]
  531. // @Tags Hosts
  532. // @Security oauth
  533. // @Param hostid path string true "Host ID"
  534. // @Param network path string true "Network name"
  535. // @Param force query bool false "Force delete"
  536. // @Success 200 {string} string "OK"
  537. // @Failure 500 {object} models.ErrorResponse
  538. func deleteHostFromNetwork(w http.ResponseWriter, r *http.Request) {
  539. var params = mux.Vars(r)
  540. hostid := params["hostid"]
  541. network := params["network"]
  542. forceDelete := r.URL.Query().Get("force") == "true"
  543. if hostid == "" || network == "" {
  544. logic.ReturnErrorResponse(
  545. w,
  546. r,
  547. logic.FormatError(errors.New("hostid or network cannot be empty"), "badrequest"),
  548. )
  549. return
  550. }
  551. // confirm host exists
  552. currHost, err := logic.GetHost(hostid)
  553. if err != nil {
  554. if database.IsEmptyRecord(err) {
  555. // check if there is any daemon nodes that needs to be deleted
  556. node, err := logic.GetNodeByHostRef(hostid, network)
  557. if err != nil {
  558. slog.Error(
  559. "couldn't get node for host",
  560. "hostid",
  561. hostid,
  562. "network",
  563. network,
  564. "error",
  565. err,
  566. )
  567. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "badrequest"))
  568. return
  569. }
  570. if err = logic.DeleteNodeByID(&node); err != nil {
  571. slog.Error("failed to force delete daemon node",
  572. "nodeid", node.ID.String(), "hostid", hostid, "network", network, "error", err)
  573. logic.ReturnErrorResponse(
  574. w,
  575. r,
  576. logic.FormatError(
  577. fmt.Errorf("failed to force delete daemon node: %s", err.Error()),
  578. "internal",
  579. ),
  580. )
  581. return
  582. }
  583. logic.ReturnSuccessResponse(w, r, "force deleted daemon node successfully")
  584. return
  585. }
  586. logger.Log(0, r.Header.Get("user"), "failed to find host:", err.Error())
  587. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  588. return
  589. }
  590. node, err := logic.UpdateHostNetwork(currHost, network, false)
  591. if err != nil {
  592. if node == nil && forceDelete {
  593. // force cleanup the node
  594. node, err := logic.GetNodeByHostRef(hostid, network)
  595. if err != nil {
  596. slog.Error(
  597. "couldn't get node for host",
  598. "hostid",
  599. hostid,
  600. "network",
  601. network,
  602. "error",
  603. err,
  604. )
  605. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "badrequest"))
  606. return
  607. }
  608. if err = logic.DeleteNodeByID(&node); err != nil {
  609. slog.Error("failed to force delete daemon node",
  610. "nodeid", node.ID.String(), "hostid", hostid, "network", network, "error", err)
  611. logic.ReturnErrorResponse(
  612. w,
  613. r,
  614. logic.FormatError(
  615. fmt.Errorf("failed to force delete daemon node: %s", err.Error()),
  616. "internal",
  617. ),
  618. )
  619. return
  620. }
  621. logic.ReturnSuccessResponse(w, r, "force deleted daemon node successfully")
  622. return
  623. }
  624. logger.Log(
  625. 0,
  626. r.Header.Get("user"),
  627. "failed to remove host from network:",
  628. hostid,
  629. network,
  630. err.Error(),
  631. )
  632. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  633. return
  634. }
  635. var gwClients []models.ExtClient
  636. if node.IsIngressGateway {
  637. gwClients = logic.GetGwExtclients(node.ID.String(), node.Network)
  638. }
  639. logger.Log(1, "deleting node", node.ID.String(), "from host", currHost.Name)
  640. if err := logic.DeleteNode(node, forceDelete); err != nil {
  641. logic.ReturnErrorResponse(
  642. w,
  643. r,
  644. logic.FormatError(fmt.Errorf("failed to delete node"), "internal"),
  645. )
  646. return
  647. }
  648. go func() {
  649. mq.PublishMqUpdatesForDeletedNode(*node, true, gwClients)
  650. if servercfg.IsDNSMode() {
  651. logic.SetDNS()
  652. }
  653. }()
  654. logic.LogEvent(&models.Event{
  655. Action: models.RemoveHostFromNet,
  656. Source: models.Subject{
  657. ID: r.Header.Get("user"),
  658. Name: r.Header.Get("user"),
  659. Type: models.UserSub,
  660. },
  661. TriggeredBy: r.Header.Get("user"),
  662. Target: models.Subject{
  663. ID: currHost.ID.String(),
  664. Name: currHost.Name,
  665. Type: models.DeviceSub,
  666. },
  667. NetworkID: models.NetworkID(network),
  668. Origin: models.Dashboard,
  669. })
  670. logger.Log(
  671. 2,
  672. r.Header.Get("user"),
  673. fmt.Sprintf("removed host %s from network %s", currHost.Name, network),
  674. )
  675. w.WriteHeader(http.StatusOK)
  676. }
  677. // @Summary To Fetch Auth Token for a Host
  678. // @Router /api/hosts/adm/authenticate [post]
  679. // @Tags Auth
  680. // @Accept json
  681. // @Param body body models.AuthParams true "Authentication parameters"
  682. // @Success 200 {object} models.SuccessResponse
  683. // @Failure 400 {object} models.ErrorResponse
  684. // @Failure 401 {object} models.ErrorResponse
  685. // @Failure 500 {object} models.ErrorResponse
  686. func authenticateHost(response http.ResponseWriter, request *http.Request) {
  687. var authRequest models.AuthParams
  688. var errorResponse = models.ErrorResponse{
  689. Code: http.StatusInternalServerError, Message: "W1R3: It's not you it's me.",
  690. }
  691. decoder := json.NewDecoder(request.Body)
  692. decoderErr := decoder.Decode(&authRequest)
  693. defer request.Body.Close()
  694. if decoderErr != nil {
  695. errorResponse.Code = http.StatusBadRequest
  696. errorResponse.Message = decoderErr.Error()
  697. logger.Log(0, request.Header.Get("user"), "error decoding request body: ",
  698. decoderErr.Error())
  699. logic.ReturnErrorResponse(response, request, errorResponse)
  700. return
  701. }
  702. errorResponse.Code = http.StatusBadRequest
  703. if authRequest.ID == "" {
  704. errorResponse.Message = "W1R3: ID can't be empty"
  705. logger.Log(0, request.Header.Get("user"), errorResponse.Message)
  706. logic.ReturnErrorResponse(response, request, errorResponse)
  707. return
  708. } else if authRequest.Password == "" {
  709. errorResponse.Message = "W1R3: Password can't be empty"
  710. logger.Log(0, request.Header.Get("user"), errorResponse.Message)
  711. logic.ReturnErrorResponse(response, request, errorResponse)
  712. return
  713. }
  714. host, err := logic.GetHost(authRequest.ID)
  715. if err != nil {
  716. errorResponse.Code = http.StatusBadRequest
  717. errorResponse.Message = err.Error()
  718. logger.Log(0, request.Header.Get("user"),
  719. "error retrieving host: ", authRequest.ID, err.Error())
  720. logic.ReturnErrorResponse(response, request, errorResponse)
  721. return
  722. }
  723. err = bcrypt.CompareHashAndPassword([]byte(host.HostPass), []byte(authRequest.Password))
  724. if err != nil {
  725. errorResponse.Code = http.StatusUnauthorized
  726. errorResponse.Message = "unauthorized"
  727. logger.Log(0, request.Header.Get("user"),
  728. "error validating user password: ", err.Error())
  729. logic.ReturnErrorResponse(response, request, errorResponse)
  730. return
  731. }
  732. tokenString, err := logic.CreateJWT(authRequest.ID, authRequest.MacAddress, "")
  733. if tokenString == "" {
  734. errorResponse.Code = http.StatusUnauthorized
  735. errorResponse.Message = "unauthorized"
  736. logger.Log(0, request.Header.Get("user"),
  737. fmt.Sprintf("%s: %v", errorResponse.Message, err))
  738. logic.ReturnErrorResponse(response, request, errorResponse)
  739. return
  740. }
  741. var successResponse = models.SuccessResponse{
  742. Code: http.StatusOK,
  743. Message: "W1R3: Host " + authRequest.ID + " Authorized",
  744. Response: models.SuccessfulLoginResponse{
  745. AuthToken: tokenString,
  746. ID: authRequest.ID,
  747. },
  748. }
  749. successJSONResponse, jsonError := json.Marshal(successResponse)
  750. if jsonError != nil {
  751. errorResponse.Code = http.StatusBadRequest
  752. errorResponse.Message = err.Error()
  753. logger.Log(0, request.Header.Get("user"),
  754. "error marshalling resp: ", err.Error())
  755. logic.ReturnErrorResponse(response, request, errorResponse)
  756. return
  757. }
  758. go func() {
  759. // Create EMQX creds
  760. if servercfg.GetBrokerType() == servercfg.EmqxBrokerType {
  761. if err := mq.GetEmqxHandler().CreateEmqxUser(host.ID.String(), authRequest.Password); err != nil {
  762. slog.Error("failed to create host credentials for EMQX: ", err.Error())
  763. }
  764. }
  765. }()
  766. response.WriteHeader(http.StatusOK)
  767. response.Header().Set("Content-Type", "application/json")
  768. response.Write(successJSONResponse)
  769. }
  770. // @Summary Send signal to peer
  771. // @Router /api/v1/host/{hostid}/signalpeer [post]
  772. // @Tags Hosts
  773. // @Security oauth
  774. // @Param hostid path string true "Host ID"
  775. // @Param body body models.Signal true "Signal data"
  776. // @Success 200 {object} models.Signal
  777. // @Failure 400 {object} models.ErrorResponse
  778. func signalPeer(w http.ResponseWriter, r *http.Request) {
  779. var params = mux.Vars(r)
  780. hostid := params["hostid"]
  781. // confirm host exists
  782. _, err := logic.GetHost(hostid)
  783. if err != nil {
  784. logger.Log(0, r.Header.Get("user"), "failed to get host:", err.Error())
  785. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "badrequest"))
  786. return
  787. }
  788. var signal models.Signal
  789. w.Header().Set("Content-Type", "application/json")
  790. err = json.NewDecoder(r.Body).Decode(&signal)
  791. if err != nil {
  792. logger.Log(0, r.Header.Get("user"), "error decoding request body: ", err.Error())
  793. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "badrequest"))
  794. return
  795. }
  796. if signal.ToHostPubKey == "" {
  797. msg := "insufficient data to signal peer"
  798. logger.Log(0, r.Header.Get("user"), msg)
  799. logic.ReturnErrorResponse(w, r, logic.FormatError(errors.New(msg), "badrequest"))
  800. return
  801. }
  802. signal.IsPro = servercfg.IsPro
  803. peerHost, err := logic.GetHost(signal.ToHostID)
  804. if err != nil {
  805. logic.ReturnErrorResponse(
  806. w,
  807. r,
  808. logic.FormatError(errors.New("failed to signal, peer not found"), "badrequest"),
  809. )
  810. return
  811. }
  812. err = mq.HostUpdate(&models.HostUpdate{
  813. Action: models.SignalHost,
  814. Host: *peerHost,
  815. Signal: signal,
  816. })
  817. if err != nil {
  818. logic.ReturnErrorResponse(
  819. w,
  820. r,
  821. logic.FormatError(
  822. errors.New("failed to publish signal to peer: "+err.Error()),
  823. "badrequest",
  824. ),
  825. )
  826. return
  827. }
  828. w.WriteHeader(http.StatusOK)
  829. json.NewEncoder(w).Encode(signal)
  830. }
  831. // @Summary Update keys for all hosts
  832. // @Router /api/hosts/keys [put]
  833. // @Tags Hosts
  834. // @Security oauth
  835. // @Success 200 {string} string "OK"
  836. // @Failure 400 {object} models.ErrorResponse
  837. func updateAllKeys(w http.ResponseWriter, r *http.Request) {
  838. var errorResponse = models.ErrorResponse{}
  839. w.Header().Set("Content-Type", "application/json")
  840. hosts, err := logic.GetAllHosts()
  841. if err != nil {
  842. errorResponse.Code = http.StatusBadRequest
  843. errorResponse.Message = err.Error()
  844. logger.Log(0, r.Header.Get("user"),
  845. "error retrieving hosts ", err.Error())
  846. logic.ReturnErrorResponse(w, r, errorResponse)
  847. return
  848. }
  849. go func() {
  850. hostUpdate := models.HostUpdate{}
  851. hostUpdate.Action = models.UpdateKeys
  852. for _, host := range hosts {
  853. hostUpdate.Host = host
  854. logger.Log(2, "updating host", host.ID.String(), " for a key update")
  855. if err = mq.HostUpdate(&hostUpdate); err != nil {
  856. logger.Log(
  857. 0,
  858. "failed to send update to node during a network wide key update",
  859. host.ID.String(),
  860. err.Error(),
  861. )
  862. }
  863. }
  864. }()
  865. logic.LogEvent(&models.Event{
  866. Action: models.RefreshAllKeys,
  867. Source: models.Subject{
  868. ID: r.Header.Get("user"),
  869. Name: r.Header.Get("user"),
  870. Type: models.UserSub,
  871. },
  872. TriggeredBy: r.Header.Get("user"),
  873. Target: models.Subject{
  874. ID: "All Devices",
  875. Name: "All Devices",
  876. Type: models.DeviceSub,
  877. },
  878. Origin: models.Dashboard,
  879. })
  880. logger.Log(2, r.Header.Get("user"), "updated keys for all hosts")
  881. w.WriteHeader(http.StatusOK)
  882. }
  883. // @Summary Update keys for a host
  884. // @Router /api/hosts/{hostid}/keys [put]
  885. // @Tags Hosts
  886. // @Security oauth
  887. // @Param hostid path string true "Host ID"
  888. // @Success 200 {string} string "OK"
  889. // @Failure 400 {object} models.ErrorResponse
  890. func updateKeys(w http.ResponseWriter, r *http.Request) {
  891. var errorResponse = models.ErrorResponse{}
  892. w.Header().Set("Content-Type", "application/json")
  893. var params = mux.Vars(r)
  894. hostid := params["hostid"]
  895. host, err := logic.GetHost(hostid)
  896. if err != nil {
  897. logger.Log(0, "failed to retrieve host", hostid, err.Error())
  898. errorResponse.Code = http.StatusBadRequest
  899. errorResponse.Message = err.Error()
  900. logger.Log(0, r.Header.Get("user"),
  901. "error retrieving hosts ", err.Error())
  902. logic.ReturnErrorResponse(w, r, errorResponse)
  903. return
  904. }
  905. go func() {
  906. hostUpdate := models.HostUpdate{
  907. Action: models.UpdateKeys,
  908. Host: *host,
  909. }
  910. if err = mq.HostUpdate(&hostUpdate); err != nil {
  911. logger.Log(0, "failed to send host key update", host.ID.String(), err.Error())
  912. }
  913. }()
  914. logic.LogEvent(&models.Event{
  915. Action: models.RefreshKey,
  916. Source: models.Subject{
  917. ID: r.Header.Get("user"),
  918. Name: r.Header.Get("user"),
  919. Type: models.UserSub,
  920. },
  921. TriggeredBy: r.Header.Get("user"),
  922. Target: models.Subject{
  923. ID: host.ID.String(),
  924. Name: host.Name,
  925. Type: models.DeviceSub,
  926. },
  927. Origin: models.Dashboard,
  928. })
  929. logger.Log(2, r.Header.Get("user"), "updated key on host", host.Name)
  930. w.WriteHeader(http.StatusOK)
  931. }
  932. // @Summary Requests all the hosts to pull
  933. // @Router /api/hosts/sync [post]
  934. // @Tags Hosts
  935. // @Security oauth
  936. // @Success 200 {string} string "sync all hosts request received"
  937. func syncHosts(w http.ResponseWriter, r *http.Request) {
  938. w.Header().Set("Content-Type", "application/json")
  939. user := r.Header.Get("user")
  940. go func() {
  941. slog.Info("requesting all hosts to sync", "user", user)
  942. hosts, err := logic.GetAllHosts()
  943. if err != nil {
  944. slog.Error("failed to retrieve all hosts", "user", user, "error", err)
  945. return
  946. }
  947. for _, host := range hosts {
  948. go func(host models.Host) {
  949. hostUpdate := models.HostUpdate{
  950. Action: models.RequestPull,
  951. Host: host,
  952. }
  953. if err = mq.HostUpdate(&hostUpdate); err != nil {
  954. slog.Error("failed to request host to sync", "user", user, "host", host.ID.String(), "error", err)
  955. } else {
  956. slog.Info("host sync requested", "user", user, "host", host.ID.String())
  957. }
  958. }(host)
  959. time.Sleep(time.Millisecond * 100)
  960. }
  961. }()
  962. logic.LogEvent(&models.Event{
  963. Action: models.SyncAll,
  964. Source: models.Subject{
  965. ID: r.Header.Get("user"),
  966. Name: r.Header.Get("user"),
  967. Type: models.UserSub,
  968. },
  969. TriggeredBy: r.Header.Get("user"),
  970. Target: models.Subject{
  971. ID: "All Devices",
  972. Name: "All Devices",
  973. Type: models.DeviceSub,
  974. },
  975. Origin: models.Dashboard,
  976. })
  977. slog.Info("sync all hosts request received", "user", user)
  978. logic.ReturnSuccessResponse(w, r, "sync all hosts request received")
  979. }
  980. // @Summary Requests a host to pull
  981. // @Router /api/hosts/{hostid}/sync [post]
  982. // @Tags Hosts
  983. // @Security oauth
  984. // @Param hostid path string true "Host ID"
  985. // @Success 200 {string} string "OK"
  986. // @Failure 400 {object} models.ErrorResponse
  987. func syncHost(w http.ResponseWriter, r *http.Request) {
  988. hostId := mux.Vars(r)["hostid"]
  989. var errorResponse = models.ErrorResponse{}
  990. w.Header().Set("Content-Type", "application/json")
  991. host, err := logic.GetHost(hostId)
  992. if err != nil {
  993. slog.Error("failed to retrieve host", "user", r.Header.Get("user"), "error", err)
  994. errorResponse.Code = http.StatusBadRequest
  995. errorResponse.Message = err.Error()
  996. logic.ReturnErrorResponse(w, r, errorResponse)
  997. return
  998. }
  999. go func() {
  1000. hostUpdate := models.HostUpdate{
  1001. Action: models.RequestPull,
  1002. Host: *host,
  1003. }
  1004. if err = mq.HostUpdate(&hostUpdate); err != nil {
  1005. slog.Error("failed to send host pull request", "host", host.ID.String(), "error", err)
  1006. }
  1007. }()
  1008. logic.LogEvent(&models.Event{
  1009. Action: models.Sync,
  1010. Source: models.Subject{
  1011. ID: r.Header.Get("user"),
  1012. Name: r.Header.Get("user"),
  1013. Type: models.UserSub,
  1014. },
  1015. TriggeredBy: r.Header.Get("user"),
  1016. Target: models.Subject{
  1017. ID: host.ID.String(),
  1018. Name: host.Name,
  1019. Type: models.DeviceSub,
  1020. },
  1021. Origin: models.Dashboard,
  1022. })
  1023. slog.Info("requested host pull", "user", r.Header.Get("user"), "host", host.ID.String())
  1024. w.WriteHeader(http.StatusOK)
  1025. }
  1026. // @Summary Deletes all EMQX hosts
  1027. // @Router /api/emqx/hosts [delete]
  1028. // @Tags Hosts
  1029. // @Security oauth
  1030. // @Success 200 {string} string "deleted hosts data on emqx"
  1031. // @Failure 500 {object} models.ErrorResponse
  1032. func delEmqxHosts(w http.ResponseWriter, r *http.Request) {
  1033. currentHosts, err := logic.GetAllHosts()
  1034. if err != nil {
  1035. logger.Log(0, r.Header.Get("user"), "failed to fetch hosts: ", err.Error())
  1036. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  1037. return
  1038. }
  1039. for _, host := range currentHosts {
  1040. // delete EMQX credentials for host
  1041. if err := mq.GetEmqxHandler().DeleteEmqxUser(host.ID.String()); err != nil {
  1042. slog.Error("failed to remove host credentials from EMQX", "id", host.ID, "error", err)
  1043. }
  1044. }
  1045. err = mq.GetEmqxHandler().DeleteEmqxUser(servercfg.GetMqUserName())
  1046. if err != nil {
  1047. slog.Error(
  1048. "failed to remove server credentials from EMQX",
  1049. "user",
  1050. servercfg.GetMqUserName(),
  1051. "error",
  1052. err,
  1053. )
  1054. }
  1055. logic.ReturnSuccessResponse(w, r, "deleted hosts data on emqx")
  1056. }
  1057. // @Summary Fetches host peerinfo
  1058. // @Router /api/host/{hostid}/peer_info [get]
  1059. // @Tags Hosts
  1060. // @Security oauth
  1061. // @Param hostid path string true "Host ID"
  1062. // @Success 200 {object} models.SuccessResponse
  1063. // @Failure 500 {object} models.ErrorResponse
  1064. func getHostPeerInfo(w http.ResponseWriter, r *http.Request) {
  1065. hostId := mux.Vars(r)["hostid"]
  1066. var errorResponse = models.ErrorResponse{}
  1067. host, err := logic.GetHost(hostId)
  1068. if err != nil {
  1069. slog.Error("failed to retrieve host", "error", err)
  1070. errorResponse.Code = http.StatusBadRequest
  1071. errorResponse.Message = err.Error()
  1072. logic.ReturnErrorResponse(w, r, errorResponse)
  1073. return
  1074. }
  1075. peerInfo, err := logic.GetHostPeerInfo(host)
  1076. if err != nil {
  1077. slog.Error("failed to retrieve host peerinfo", "error", err)
  1078. errorResponse.Code = http.StatusBadRequest
  1079. errorResponse.Message = err.Error()
  1080. logic.ReturnErrorResponse(w, r, errorResponse)
  1081. return
  1082. }
  1083. logic.ReturnSuccessResponseWithJson(w, r, peerInfo, "fetched host peer info")
  1084. }