hosts.go 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376
  1. package controller
  2. import (
  3. "encoding/json"
  4. "errors"
  5. "fmt"
  6. "net/http"
  7. "reflect"
  8. "github.com/gorilla/mux"
  9. "github.com/gravitl/netmaker/logger"
  10. "github.com/gravitl/netmaker/logic"
  11. "github.com/gravitl/netmaker/models"
  12. "github.com/gravitl/netmaker/mq"
  13. "golang.org/x/crypto/bcrypt"
  14. )
  15. type hostNetworksUpdatePayload struct {
  16. Networks []string `json:"networks"`
  17. }
  18. func hostHandlers(r *mux.Router) {
  19. r.HandleFunc("/api/hosts", logic.SecurityCheck(true, http.HandlerFunc(getHosts))).Methods(http.MethodGet)
  20. r.HandleFunc("/api/hosts/{hostid}", logic.SecurityCheck(true, http.HandlerFunc(updateHost))).Methods(http.MethodPut)
  21. r.HandleFunc("/api/hosts/{hostid}", logic.SecurityCheck(true, http.HandlerFunc(deleteHost))).Methods(http.MethodDelete)
  22. r.HandleFunc("/api/hosts/{hostid}/networks/{network}", logic.SecurityCheck(true, http.HandlerFunc(addHostToNetwork))).Methods(http.MethodPost)
  23. r.HandleFunc("/api/hosts/{hostid}/networks/{network}", logic.SecurityCheck(true, http.HandlerFunc(deleteHostFromNetwork))).Methods(http.MethodDelete)
  24. r.HandleFunc("/api/hosts/{hostid}/relay", logic.SecurityCheck(false, http.HandlerFunc(createHostRelay))).Methods(http.MethodPost)
  25. r.HandleFunc("/api/hosts/{hostid}/relay", logic.SecurityCheck(false, http.HandlerFunc(deleteHostRelay))).Methods(http.MethodDelete)
  26. r.HandleFunc("/api/hosts/adm/authenticate", authenticateHost).Methods(http.MethodPost)
  27. }
  28. // swagger:route GET /api/hosts hosts getHosts
  29. //
  30. // Lists all hosts.
  31. //
  32. // Schemes: https
  33. //
  34. // Security:
  35. // oauth
  36. //
  37. // Responses:
  38. // 200: getHostsSliceResponse
  39. func getHosts(w http.ResponseWriter, r *http.Request) {
  40. currentHosts, err := logic.GetAllHosts()
  41. if err != nil {
  42. logger.Log(0, r.Header.Get("user"), "failed to fetch hosts: ", err.Error())
  43. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  44. return
  45. }
  46. // return JSON/API formatted hosts
  47. apiHosts := logic.GetAllHostsAPI(currentHosts[:])
  48. logger.Log(2, r.Header.Get("user"), "fetched all hosts")
  49. w.WriteHeader(http.StatusOK)
  50. json.NewEncoder(w).Encode(apiHosts)
  51. }
  52. // swagger:route PUT /api/hosts/{hostid} hosts updateHost
  53. //
  54. // Updates a Netclient host on Netmaker server.
  55. //
  56. // Schemes: https
  57. //
  58. // Security:
  59. // oauth
  60. //
  61. // Responses:
  62. // 200: updateHostResponse
  63. func updateHost(w http.ResponseWriter, r *http.Request) {
  64. var newHostData models.ApiHost
  65. err := json.NewDecoder(r.Body).Decode(&newHostData)
  66. if err != nil {
  67. logger.Log(0, r.Header.Get("user"), "failed to update a host:", err.Error())
  68. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  69. return
  70. }
  71. // confirm host exists
  72. currHost, err := logic.GetHost(newHostData.ID)
  73. if err != nil {
  74. logger.Log(0, r.Header.Get("user"), "failed to update a host:", err.Error())
  75. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  76. return
  77. }
  78. newHost := newHostData.ConvertAPIHostToNMHost(currHost)
  79. // check if relay information is changed
  80. updateRelay := false
  81. if newHost.IsRelay && len(newHost.RelayedHosts) > 0 {
  82. if len(newHost.RelayedHosts) != len(currHost.RelayedHosts) || !reflect.DeepEqual(newHost.RelayedHosts, currHost.RelayedHosts) {
  83. updateRelay = true
  84. }
  85. }
  86. logic.UpdateHost(newHost, currHost) // update the in memory struct values
  87. if err = logic.UpsertHost(newHost); err != nil {
  88. logger.Log(0, r.Header.Get("user"), "failed to update a host:", err.Error())
  89. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  90. return
  91. }
  92. if updateRelay {
  93. logic.UpdateHostRelay(currHost.ID.String(), currHost.RelayedHosts, newHost.RelayedHosts)
  94. }
  95. newNetworks := logic.GetHostNetworks(newHost.ID.String())
  96. if len(newNetworks) > 0 {
  97. if err = mq.ModifyClient(&mq.MqClient{
  98. ID: currHost.ID.String(),
  99. Text: currHost.Name,
  100. Networks: newNetworks,
  101. }); err != nil {
  102. logger.Log(0, r.Header.Get("user"), "failed to update host networks roles in DynSec:", err.Error())
  103. }
  104. }
  105. // publish host update through MQ
  106. if err := mq.HostUpdate(&models.HostUpdate{
  107. Action: models.UpdateHost,
  108. Host: *newHost,
  109. }); err != nil {
  110. logger.Log(0, r.Header.Get("user"), "failed to send host update: ", currHost.ID.String(), err.Error())
  111. }
  112. go func() {
  113. if err := mq.PublishPeerUpdate(); err != nil {
  114. logger.Log(0, "fail to publish peer update: ", err.Error())
  115. }
  116. }()
  117. apiHostData := newHost.ConvertNMHostToAPI()
  118. logger.Log(2, r.Header.Get("user"), "updated host", newHost.ID.String())
  119. w.WriteHeader(http.StatusOK)
  120. json.NewEncoder(w).Encode(apiHostData)
  121. }
  122. // swagger:route DELETE /api/hosts/{hostid} hosts deleteHost
  123. //
  124. // Deletes a Netclient host from Netmaker server.
  125. //
  126. // Schemes: https
  127. //
  128. // Security:
  129. // oauth
  130. //
  131. // Responses:
  132. // 200: deleteHostResponse
  133. func deleteHost(w http.ResponseWriter, r *http.Request) {
  134. var params = mux.Vars(r)
  135. hostid := params["hostid"]
  136. // confirm host exists
  137. currHost, err := logic.GetHost(hostid)
  138. if err != nil {
  139. logger.Log(0, r.Header.Get("user"), "failed to delete a host:", err.Error())
  140. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  141. return
  142. }
  143. if err = logic.RemoveHost(currHost); err != nil {
  144. logger.Log(0, r.Header.Get("user"), "failed to delete a host:", err.Error())
  145. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  146. return
  147. }
  148. if err = mq.HostUpdate(&models.HostUpdate{
  149. Action: models.DeleteHost,
  150. Host: *currHost,
  151. }); err != nil {
  152. logger.Log(0, r.Header.Get("user"), "failed to send delete host update: ", currHost.ID.String(), err.Error())
  153. }
  154. if err = mq.DeleteMqClient(currHost.ID.String()); err != nil {
  155. logger.Log(0, "error removing DynSec credentials for host:", currHost.Name, err.Error())
  156. }
  157. apiHostData := currHost.ConvertNMHostToAPI()
  158. logger.Log(2, r.Header.Get("user"), "removed host", currHost.Name)
  159. w.WriteHeader(http.StatusOK)
  160. json.NewEncoder(w).Encode(apiHostData)
  161. }
  162. // swagger:route POST /api/hosts/{hostid}/networks/{network} hosts addHostToNetwork
  163. //
  164. // Given a network, a host is added to the network.
  165. //
  166. // Schemes: https
  167. //
  168. // Security:
  169. // oauth
  170. //
  171. // Responses:
  172. // 200: addHostToNetworkResponse
  173. func addHostToNetwork(w http.ResponseWriter, r *http.Request) {
  174. var params = mux.Vars(r)
  175. hostid := params["hostid"]
  176. network := params["network"]
  177. if hostid == "" || network == "" {
  178. logic.ReturnErrorResponse(w, r, logic.FormatError(errors.New("hostid or network cannot be empty"), "badrequest"))
  179. return
  180. }
  181. // confirm host exists
  182. currHost, err := logic.GetHost(hostid)
  183. if err != nil {
  184. logger.Log(0, r.Header.Get("user"), "failed to find host:", hostid, err.Error())
  185. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  186. return
  187. }
  188. newNode, err := logic.UpdateHostNetwork(currHost, network, true)
  189. if err != nil {
  190. logger.Log(0, r.Header.Get("user"), "failed to add host to network:", hostid, network, err.Error())
  191. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  192. return
  193. }
  194. logger.Log(1, "added new node", newNode.ID.String(), "to host", currHost.Name)
  195. if err = mq.HostUpdate(&models.HostUpdate{
  196. Action: models.JoinHostToNetwork,
  197. Host: *currHost,
  198. Node: *newNode,
  199. }); err != nil {
  200. logger.Log(0, r.Header.Get("user"), "failed to update host to join network:", hostid, network, err.Error())
  201. }
  202. networks := logic.GetHostNetworks(currHost.ID.String())
  203. if len(networks) > 0 {
  204. if err = mq.ModifyClient(&mq.MqClient{
  205. ID: currHost.ID.String(),
  206. Text: currHost.Name,
  207. Networks: networks,
  208. }); err != nil {
  209. logger.Log(0, r.Header.Get("user"), "failed to update host networks roles in DynSec:", hostid, err.Error())
  210. }
  211. }
  212. logger.Log(2, r.Header.Get("user"), fmt.Sprintf("added host %s to network %s", currHost.Name, network))
  213. w.WriteHeader(http.StatusOK)
  214. }
  215. // swagger:route DELETE /api/hosts/{hostid}/networks/{network} hosts deleteHostFromNetwork
  216. //
  217. // Given a network, a host is removed from the network.
  218. //
  219. // Schemes: https
  220. //
  221. // Security:
  222. // oauth
  223. //
  224. // Responses:
  225. // 200: deleteHostFromNetworkResponse
  226. func deleteHostFromNetwork(w http.ResponseWriter, r *http.Request) {
  227. var params = mux.Vars(r)
  228. hostid := params["hostid"]
  229. network := params["network"]
  230. if hostid == "" || network == "" {
  231. logic.ReturnErrorResponse(w, r, logic.FormatError(errors.New("hostid or network cannot be empty"), "badrequest"))
  232. return
  233. }
  234. // confirm host exists
  235. currHost, err := logic.GetHost(hostid)
  236. if err != nil {
  237. logger.Log(0, r.Header.Get("user"), "failed to find host:", err.Error())
  238. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  239. return
  240. }
  241. node, err := logic.UpdateHostNetwork(currHost, network, false)
  242. if err != nil {
  243. logger.Log(0, r.Header.Get("user"), "failed to remove host from network:", hostid, network, err.Error())
  244. logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
  245. return
  246. }
  247. logger.Log(1, "deleting node", node.ID.String(), "from host", currHost.Name)
  248. if err := logic.DeleteNode(node, false); err != nil {
  249. logic.ReturnErrorResponse(w, r, logic.FormatError(fmt.Errorf("failed to delete node"), "internal"))
  250. return
  251. }
  252. // notify node change
  253. runUpdates(node, false)
  254. go func() { // notify of peer change
  255. if err := mq.PublishPeerUpdate(); err != nil {
  256. logger.Log(1, "error publishing peer update ", err.Error())
  257. }
  258. }()
  259. logger.Log(2, r.Header.Get("user"), fmt.Sprintf("removed host %s from network %s", currHost.Name, network))
  260. w.WriteHeader(http.StatusOK)
  261. }
  262. // swagger:route POST /api/hosts/adm/authenticate hosts authenticateHost
  263. //
  264. // Host based authentication for making further API calls.
  265. //
  266. // Schemes: https
  267. //
  268. // Security:
  269. // oauth
  270. //
  271. // Responses:
  272. // 200: successResponse
  273. func authenticateHost(response http.ResponseWriter, request *http.Request) {
  274. var authRequest models.AuthParams
  275. var errorResponse = models.ErrorResponse{
  276. Code: http.StatusInternalServerError, Message: "W1R3: It's not you it's me.",
  277. }
  278. decoder := json.NewDecoder(request.Body)
  279. decoderErr := decoder.Decode(&authRequest)
  280. defer request.Body.Close()
  281. if decoderErr != nil {
  282. errorResponse.Code = http.StatusBadRequest
  283. errorResponse.Message = decoderErr.Error()
  284. logger.Log(0, request.Header.Get("user"), "error decoding request body: ",
  285. decoderErr.Error())
  286. logic.ReturnErrorResponse(response, request, errorResponse)
  287. return
  288. }
  289. errorResponse.Code = http.StatusBadRequest
  290. if authRequest.ID == "" {
  291. errorResponse.Message = "W1R3: ID can't be empty"
  292. logger.Log(0, request.Header.Get("user"), errorResponse.Message)
  293. logic.ReturnErrorResponse(response, request, errorResponse)
  294. return
  295. } else if authRequest.Password == "" {
  296. errorResponse.Message = "W1R3: Password can't be empty"
  297. logger.Log(0, request.Header.Get("user"), errorResponse.Message)
  298. logic.ReturnErrorResponse(response, request, errorResponse)
  299. return
  300. }
  301. host, err := logic.GetHost(authRequest.ID)
  302. if err != nil {
  303. errorResponse.Code = http.StatusBadRequest
  304. errorResponse.Message = err.Error()
  305. logger.Log(0, request.Header.Get("user"),
  306. "error retrieving host: ", err.Error())
  307. logic.ReturnErrorResponse(response, request, errorResponse)
  308. return
  309. }
  310. err = bcrypt.CompareHashAndPassword([]byte(host.HostPass), []byte(authRequest.Password))
  311. if err != nil {
  312. errorResponse.Code = http.StatusUnauthorized
  313. errorResponse.Message = "unauthorized"
  314. logger.Log(0, request.Header.Get("user"),
  315. "error validating user password: ", err.Error())
  316. logic.ReturnErrorResponse(response, request, errorResponse)
  317. return
  318. }
  319. tokenString, err := logic.CreateJWT(authRequest.ID, authRequest.MacAddress, "")
  320. if tokenString == "" {
  321. errorResponse.Code = http.StatusUnauthorized
  322. errorResponse.Message = "unauthorized"
  323. logger.Log(0, request.Header.Get("user"),
  324. fmt.Sprintf("%s: %v", errorResponse.Message, err))
  325. logic.ReturnErrorResponse(response, request, errorResponse)
  326. return
  327. }
  328. var successResponse = models.SuccessResponse{
  329. Code: http.StatusOK,
  330. Message: "W1R3: Host " + authRequest.ID + " Authorized",
  331. Response: models.SuccessfulLoginResponse{
  332. AuthToken: tokenString,
  333. ID: authRequest.ID,
  334. },
  335. }
  336. successJSONResponse, jsonError := json.Marshal(successResponse)
  337. if jsonError != nil {
  338. errorResponse.Code = http.StatusBadRequest
  339. errorResponse.Message = err.Error()
  340. logger.Log(0, request.Header.Get("user"),
  341. "error marshalling resp: ", err.Error())
  342. logic.ReturnErrorResponse(response, request, errorResponse)
  343. return
  344. }
  345. response.WriteHeader(http.StatusOK)
  346. response.Header().Set("Content-Type", "application/json")
  347. response.Write(successJSONResponse)
  348. }