dnsHttpController.go 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450
  1. package controller
  2. import (
  3. "encoding/json"
  4. "net/http"
  5. "strings"
  6. "github.com/go-playground/validator/v10"
  7. "github.com/gorilla/mux"
  8. "github.com/gravitl/netmaker/database"
  9. "github.com/gravitl/netmaker/functions"
  10. "github.com/gravitl/netmaker/logic"
  11. "github.com/gravitl/netmaker/models"
  12. )
  13. func dnsHandlers(r *mux.Router) {
  14. r.HandleFunc("/api/dns", securityCheckDNS(true, true, http.HandlerFunc(getAllDNS))).Methods("GET")
  15. r.HandleFunc("/api/dns/adm/{network}/nodes", securityCheckDNS(false, true, http.HandlerFunc(getNodeDNS))).Methods("GET")
  16. r.HandleFunc("/api/dns/adm/{network}/custom", securityCheckDNS(false, true, http.HandlerFunc(getCustomDNS))).Methods("GET")
  17. r.HandleFunc("/api/dns/adm/{network}", securityCheckDNS(false, true, http.HandlerFunc(getDNS))).Methods("GET")
  18. r.HandleFunc("/api/dns/{network}", securityCheckDNS(false, false, http.HandlerFunc(createDNS))).Methods("POST")
  19. r.HandleFunc("/api/dns/adm/pushdns", securityCheckDNS(false, false, http.HandlerFunc(pushDNS))).Methods("POST")
  20. r.HandleFunc("/api/dns/{network}/{domain}", securityCheckDNS(false, false, http.HandlerFunc(deleteDNS))).Methods("DELETE")
  21. r.HandleFunc("/api/dns/{network}/{domain}", securityCheckDNS(false, false, http.HandlerFunc(updateDNS))).Methods("PUT")
  22. }
  23. //Gets all nodes associated with network, including pending nodes
  24. func getNodeDNS(w http.ResponseWriter, r *http.Request) {
  25. w.Header().Set("Content-Type", "application/json")
  26. var dns []models.DNSEntry
  27. var params = mux.Vars(r)
  28. dns, err := GetNodeDNS(params["network"])
  29. if err != nil {
  30. returnErrorResponse(w, r, formatError(err, "internal"))
  31. return
  32. }
  33. //Returns all the nodes in JSON format
  34. w.WriteHeader(http.StatusOK)
  35. json.NewEncoder(w).Encode(dns)
  36. }
  37. //Gets all nodes associated with network, including pending nodes
  38. func getAllDNS(w http.ResponseWriter, r *http.Request) {
  39. w.Header().Set("Content-Type", "application/json")
  40. dns, err := GetAllDNS()
  41. if err != nil {
  42. returnErrorResponse(w, r, formatError(err, "internal"))
  43. return
  44. }
  45. //Returns all the nodes in JSON format
  46. w.WriteHeader(http.StatusOK)
  47. json.NewEncoder(w).Encode(dns)
  48. }
  49. // GetAllDNS - gets all dns entries
  50. func GetAllDNS() ([]models.DNSEntry, error) {
  51. var dns []models.DNSEntry
  52. networks, err := logic.GetNetworks()
  53. if err != nil && !database.IsEmptyRecord(err) {
  54. return []models.DNSEntry{}, err
  55. }
  56. for _, net := range networks {
  57. netdns, err := logic.GetDNS(net.NetID)
  58. if err != nil {
  59. return []models.DNSEntry{}, nil
  60. }
  61. dns = append(dns, netdns...)
  62. }
  63. return dns, nil
  64. }
  65. // GetNodeDNS - gets node dns
  66. func GetNodeDNS(network string) ([]models.DNSEntry, error) {
  67. var dns []models.DNSEntry
  68. collection, err := database.FetchRecords(database.NODES_TABLE_NAME)
  69. if err != nil {
  70. return dns, err
  71. }
  72. for _, value := range collection {
  73. var entry models.DNSEntry
  74. var node models.Node
  75. if err = json.Unmarshal([]byte(value), &node); err != nil {
  76. continue
  77. }
  78. if err = json.Unmarshal([]byte(value), &entry); node.Network == network && err == nil {
  79. dns = append(dns, entry)
  80. }
  81. }
  82. return dns, nil
  83. }
  84. //Gets all nodes associated with network, including pending nodes
  85. func getCustomDNS(w http.ResponseWriter, r *http.Request) {
  86. w.Header().Set("Content-Type", "application/json")
  87. var dns []models.DNSEntry
  88. var params = mux.Vars(r)
  89. dns, err := logic.GetCustomDNS(params["network"])
  90. if err != nil {
  91. returnErrorResponse(w, r, formatError(err, "internal"))
  92. return
  93. }
  94. //Returns all the nodes in JSON format
  95. w.WriteHeader(http.StatusOK)
  96. json.NewEncoder(w).Encode(dns)
  97. }
  98. // GetDNSEntryNum - gets which entry the dns was
  99. func GetDNSEntryNum(domain string, network string) (int, error) {
  100. num := 0
  101. entries, err := logic.GetDNS(network)
  102. if err != nil {
  103. return 0, err
  104. }
  105. for i := 0; i < len(entries); i++ {
  106. if domain == entries[i].Name {
  107. num++
  108. }
  109. }
  110. return num, nil
  111. }
  112. // Gets all nodes associated with network, including pending nodes
  113. func getDNS(w http.ResponseWriter, r *http.Request) {
  114. w.Header().Set("Content-Type", "application/json")
  115. var dns []models.DNSEntry
  116. var params = mux.Vars(r)
  117. dns, err := logic.GetDNS(params["network"])
  118. if err != nil {
  119. returnErrorResponse(w, r, formatError(err, "internal"))
  120. return
  121. }
  122. w.WriteHeader(http.StatusOK)
  123. json.NewEncoder(w).Encode(dns)
  124. }
  125. func createDNS(w http.ResponseWriter, r *http.Request) {
  126. w.Header().Set("Content-Type", "application/json")
  127. var entry models.DNSEntry
  128. var params = mux.Vars(r)
  129. //get node from body of request
  130. _ = json.NewDecoder(r.Body).Decode(&entry)
  131. entry.Network = params["network"]
  132. err := ValidateDNSCreate(entry)
  133. if err != nil {
  134. returnErrorResponse(w, r, formatError(err, "badrequest"))
  135. return
  136. }
  137. entry, err = CreateDNS(entry)
  138. if err != nil {
  139. returnErrorResponse(w, r, formatError(err, "internal"))
  140. return
  141. }
  142. err = logic.SetDNS()
  143. if err != nil {
  144. returnErrorResponse(w, r, formatError(err, "internal"))
  145. return
  146. }
  147. w.WriteHeader(http.StatusOK)
  148. json.NewEncoder(w).Encode(entry)
  149. }
  150. func updateDNS(w http.ResponseWriter, r *http.Request) {
  151. w.Header().Set("Content-Type", "application/json")
  152. var params = mux.Vars(r)
  153. var entry models.DNSEntry
  154. //start here
  155. entry, err := GetDNSEntry(params["domain"], params["network"])
  156. if err != nil {
  157. returnErrorResponse(w, r, formatError(err, "badrequest"))
  158. return
  159. }
  160. var dnschange models.DNSEntry
  161. // we decode our body request params
  162. err = json.NewDecoder(r.Body).Decode(&dnschange)
  163. if err != nil {
  164. returnErrorResponse(w, r, formatError(err, "badrequest"))
  165. return
  166. }
  167. // fill in any missing fields
  168. if dnschange.Name == "" {
  169. dnschange.Name = entry.Name
  170. }
  171. if dnschange.Network == "" {
  172. dnschange.Network = entry.Network
  173. }
  174. if dnschange.Address == "" {
  175. dnschange.Address = entry.Address
  176. }
  177. err = ValidateDNSUpdate(dnschange, entry)
  178. if err != nil {
  179. returnErrorResponse(w, r, formatError(err, "badrequest"))
  180. return
  181. }
  182. entry, err = UpdateDNS(dnschange, entry)
  183. if err != nil {
  184. returnErrorResponse(w, r, formatError(err, "badrequest"))
  185. return
  186. }
  187. err = logic.SetDNS()
  188. if err != nil {
  189. returnErrorResponse(w, r, formatError(err, "internal"))
  190. return
  191. }
  192. json.NewEncoder(w).Encode(entry)
  193. }
  194. func deleteDNS(w http.ResponseWriter, r *http.Request) {
  195. // Set header
  196. w.Header().Set("Content-Type", "application/json")
  197. // get params
  198. var params = mux.Vars(r)
  199. err := DeleteDNS(params["domain"], params["network"])
  200. if err != nil {
  201. returnErrorResponse(w, r, formatError(err, "internal"))
  202. return
  203. }
  204. entrytext := params["domain"] + "." + params["network"]
  205. functions.PrintUserLog(models.NODE_SERVER_NAME, "deleted dns entry: "+entrytext, 1)
  206. err = logic.SetDNS()
  207. if err != nil {
  208. returnErrorResponse(w, r, formatError(err, "internal"))
  209. return
  210. }
  211. json.NewEncoder(w).Encode(entrytext + " deleted.")
  212. }
  213. // CreateDNS - creates a DNS entry
  214. func CreateDNS(entry models.DNSEntry) (models.DNSEntry, error) {
  215. data, err := json.Marshal(&entry)
  216. if err != nil {
  217. return models.DNSEntry{}, err
  218. }
  219. key, err := logic.GetRecordKey(entry.Name, entry.Network)
  220. if err != nil {
  221. return models.DNSEntry{}, err
  222. }
  223. err = database.Insert(key, string(data), database.DNS_TABLE_NAME)
  224. return entry, err
  225. }
  226. // GetDNSEntry - gets a DNS entry
  227. func GetDNSEntry(domain string, network string) (models.DNSEntry, error) {
  228. var entry models.DNSEntry
  229. key, err := logic.GetRecordKey(domain, network)
  230. if err != nil {
  231. return entry, err
  232. }
  233. record, err := database.FetchRecord(database.DNS_TABLE_NAME, key)
  234. if err != nil {
  235. return entry, err
  236. }
  237. err = json.Unmarshal([]byte(record), &entry)
  238. return entry, err
  239. }
  240. // UpdateDNS - updates DNS entry
  241. func UpdateDNS(dnschange models.DNSEntry, entry models.DNSEntry) (models.DNSEntry, error) {
  242. key, err := logic.GetRecordKey(entry.Name, entry.Network)
  243. if err != nil {
  244. return entry, err
  245. }
  246. if dnschange.Name != "" {
  247. entry.Name = dnschange.Name
  248. }
  249. if dnschange.Address != "" {
  250. entry.Address = dnschange.Address
  251. }
  252. newkey, err := logic.GetRecordKey(entry.Name, entry.Network)
  253. err = database.DeleteRecord(database.DNS_TABLE_NAME, key)
  254. if err != nil {
  255. return entry, err
  256. }
  257. data, err := json.Marshal(&entry)
  258. err = database.Insert(newkey, string(data), database.DNS_TABLE_NAME)
  259. return entry, err
  260. }
  261. // DeleteDNS - deletes a DNS entry
  262. func DeleteDNS(domain string, network string) error {
  263. key, err := logic.GetRecordKey(domain, network)
  264. if err != nil {
  265. return err
  266. }
  267. err = database.DeleteRecord(database.DNS_TABLE_NAME, key)
  268. return err
  269. }
  270. func pushDNS(w http.ResponseWriter, r *http.Request) {
  271. // Set header
  272. w.Header().Set("Content-Type", "application/json")
  273. err := logic.SetDNS()
  274. if err != nil {
  275. returnErrorResponse(w, r, formatError(err, "internal"))
  276. return
  277. }
  278. functions.PrintUserLog(r.Header.Get("user"), "pushed DNS updates to nameserver", 1)
  279. json.NewEncoder(w).Encode("DNS Pushed to CoreDNS")
  280. }
  281. // ValidateDNSCreate - checks if an entry is valid
  282. func ValidateDNSCreate(entry models.DNSEntry) error {
  283. v := validator.New()
  284. _ = v.RegisterValidation("name_unique", func(fl validator.FieldLevel) bool {
  285. num, err := GetDNSEntryNum(entry.Name, entry.Network)
  286. return err == nil && num == 0
  287. })
  288. _ = v.RegisterValidation("network_exists", func(fl validator.FieldLevel) bool {
  289. _, err := logic.GetParentNetwork(entry.Network)
  290. return err == nil
  291. })
  292. err := v.Struct(entry)
  293. if err != nil {
  294. for _, e := range err.(validator.ValidationErrors) {
  295. functions.PrintUserLog("", e.Error(), 1)
  296. }
  297. }
  298. return err
  299. }
  300. // ValidateDNSUpdate - validates a DNS update
  301. func ValidateDNSUpdate(change models.DNSEntry, entry models.DNSEntry) error {
  302. v := validator.New()
  303. _ = v.RegisterValidation("name_unique", func(fl validator.FieldLevel) bool {
  304. //if name & net not changing name we are good
  305. if change.Name == entry.Name && change.Network == entry.Network {
  306. return true
  307. }
  308. num, err := GetDNSEntryNum(change.Name, change.Network)
  309. return err == nil && num == 0
  310. })
  311. _ = v.RegisterValidation("network_exists", func(fl validator.FieldLevel) bool {
  312. _, err := logic.GetParentNetwork(change.Network)
  313. if err != nil {
  314. functions.PrintUserLog("", err.Error(), 0)
  315. }
  316. return err == nil
  317. })
  318. // _ = v.RegisterValidation("name_valid", func(fl validator.FieldLevel) bool {
  319. // isvalid := functions.NameInDNSCharSet(entry.Name)
  320. // notEmptyCheck := entry.Name != ""
  321. // return isvalid && notEmptyCheck
  322. // })
  323. //
  324. // _ = v.RegisterValidation("address_valid", func(fl validator.FieldLevel) bool {
  325. // isValid := true
  326. // if entry.Address != "" {
  327. // isValid = functions.IsIpNet(entry.Address)
  328. // }
  329. // return isValid
  330. // })
  331. err := v.Struct(change)
  332. if err != nil {
  333. for _, e := range err.(validator.ValidationErrors) {
  334. functions.PrintUserLog("", e.Error(), 1)
  335. }
  336. }
  337. return err
  338. }
  339. //Security check DNS is middleware for every DNS function and just checks to make sure that its the master or dns token calling
  340. //Only admin should have access to all these network-level actions
  341. //DNS token should have access to only read functions
  342. func securityCheckDNS(reqAdmin bool, allowDNSToken bool, next http.Handler) http.HandlerFunc {
  343. return func(w http.ResponseWriter, r *http.Request) {
  344. var errorResponse = models.ErrorResponse{
  345. Code: http.StatusUnauthorized, Message: "W1R3: It's not you it's me.",
  346. }
  347. var params = mux.Vars(r)
  348. bearerToken := r.Header.Get("Authorization")
  349. if allowDNSToken && authenticateDNSToken(bearerToken) {
  350. r.Header.Set("user", "nameserver")
  351. networks, _ := json.Marshal([]string{ALL_NETWORK_ACCESS})
  352. r.Header.Set("networks", string(networks))
  353. next.ServeHTTP(w, r)
  354. } else {
  355. err, networks, username := SecurityCheck(reqAdmin, params["networkname"], bearerToken)
  356. if err != nil {
  357. if strings.Contains(err.Error(), "does not exist") {
  358. errorResponse.Code = http.StatusNotFound
  359. }
  360. errorResponse.Message = err.Error()
  361. returnErrorResponse(w, r, errorResponse)
  362. return
  363. }
  364. networksJson, err := json.Marshal(&networks)
  365. if err != nil {
  366. errorResponse.Message = err.Error()
  367. returnErrorResponse(w, r, errorResponse)
  368. return
  369. }
  370. r.Header.Set("user", username)
  371. r.Header.Set("networks", string(networksJson))
  372. next.ServeHTTP(w, r)
  373. }
  374. }
  375. }