| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489 |
- package api
- import (
- "encoding/base64"
- "encoding/json"
- "net/http"
- "strconv"
- "strings"
- "time"
- "github.com/porter-dev/porter/internal/oauth"
- "github.com/porter-dev/porter/internal/registry"
- "github.com/go-chi/chi"
- "github.com/porter-dev/porter/internal/forms"
- "github.com/porter-dev/porter/internal/models"
- "github.com/aws/aws-sdk-go/service/ecr"
- )
- // HandleCreateRegistry creates a new registry
- func (app *App) HandleCreateRegistry(w http.ResponseWriter, r *http.Request) {
- projID, err := strconv.ParseUint(chi.URLParam(r, "project_id"), 0, 64)
- if err != nil || projID == 0 {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- form := &forms.CreateRegistry{
- ProjectID: uint(projID),
- }
- // decode from JSON to form value
- if err := json.NewDecoder(r.Body).Decode(form); err != nil {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- // validate the form
- if err := app.validator.Struct(form); err != nil {
- app.handleErrorFormValidation(err, ErrProjectValidateFields, w)
- return
- }
- // convert the form to a registry
- registry, err := form.ToRegistry(app.Repo)
- if err != nil {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- // handle write to the database
- registry, err = app.Repo.Registry().CreateRegistry(registry)
- if err != nil {
- app.handleErrorDataWrite(err, w)
- return
- }
- app.Logger.Info().Msgf("New registry created: %d", registry.ID)
- w.WriteHeader(http.StatusCreated)
- regExt := registry.Externalize()
- if err := json.NewEncoder(w).Encode(regExt); err != nil {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- }
- // HandleListProjectRegistries returns a list of registries for a project
- func (app *App) HandleListProjectRegistries(w http.ResponseWriter, r *http.Request) {
- projID, err := strconv.ParseUint(chi.URLParam(r, "project_id"), 0, 64)
- if err != nil || projID == 0 {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- regs, err := app.Repo.Registry().ListRegistriesByProjectID(uint(projID))
- if err != nil {
- app.handleErrorRead(err, ErrProjectDataRead, w)
- return
- }
- extRegs := make([]*models.RegistryExternal, 0)
- for _, reg := range regs {
- extRegs = append(extRegs, reg.Externalize())
- }
- w.WriteHeader(http.StatusOK)
- if err := json.NewEncoder(w).Encode(extRegs); err != nil {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- }
- // temp -- token response
- type RegTokenResponse struct {
- Token string `json:"token"`
- ExpiresAt *time.Time `json:"expires_at"`
- }
- // HandleGetProjectRegistryECRToken gets an ECR token for a registry
- func (app *App) HandleGetProjectRegistryECRToken(w http.ResponseWriter, r *http.Request) {
- projID, err := strconv.ParseUint(chi.URLParam(r, "project_id"), 0, 64)
- if err != nil || projID == 0 {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- region := chi.URLParam(r, "region")
- if region == "" {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- // list registries and find one that matches the region
- regs, err := app.Repo.Registry().ListRegistriesByProjectID(uint(projID))
- var token string
- var expiresAt *time.Time
- for _, reg := range regs {
- if reg.AWSIntegrationID != 0 {
- awsInt, err := app.Repo.AWSIntegration().ReadAWSIntegration(reg.AWSIntegrationID)
- if err != nil {
- app.handleErrorDataRead(err, w)
- return
- }
- if awsInt.AWSRegion == region {
- // get the aws integration and session
- sess, err := awsInt.GetSession()
- if err != nil {
- app.handleErrorDataRead(err, w)
- return
- }
- ecrSvc := ecr.New(sess)
- output, err := ecrSvc.GetAuthorizationToken(&ecr.GetAuthorizationTokenInput{})
- if err != nil {
- app.handleErrorDataRead(err, w)
- return
- }
- token = *output.AuthorizationData[0].AuthorizationToken
- expiresAt = output.AuthorizationData[0].ExpiresAt
- }
- }
- }
- resp := &RegTokenResponse{
- Token: token,
- ExpiresAt: expiresAt,
- }
- w.WriteHeader(http.StatusOK)
- if err := json.NewEncoder(w).Encode(resp); err != nil {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- }
- // HandleGetProjectRegistryDockerhubToken gets a Dockerhub token for a registry
- func (app *App) HandleGetProjectRegistryDockerhubToken(w http.ResponseWriter, r *http.Request) {
- projID, err := strconv.ParseUint(chi.URLParam(r, "project_id"), 0, 64)
- if err != nil || projID == 0 {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- // list registries and find one that matches the region
- regs, err := app.Repo.Registry().ListRegistriesByProjectID(uint(projID))
- var token string
- var expiresAt *time.Time
- for _, reg := range regs {
- if reg.BasicIntegrationID != 0 && strings.Contains(reg.URL, "index.docker.io") {
- basic, err := app.Repo.BasicIntegration().ReadBasicIntegration(reg.BasicIntegrationID)
- if err != nil {
- app.handleErrorDataRead(err, w)
- return
- }
- token = base64.StdEncoding.EncodeToString([]byte(string(basic.Username) + ":" + string(basic.Password)))
- // we'll just set an arbitrary 30-day expiry time (this is not enforced)
- timeExpires := time.Now().Add(30 * 24 * 3600 * time.Second)
- expiresAt = &timeExpires
- }
- }
- resp := &RegTokenResponse{
- Token: token,
- ExpiresAt: expiresAt,
- }
- w.WriteHeader(http.StatusOK)
- if err := json.NewEncoder(w).Encode(resp); err != nil {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- }
- type GCRTokenRequestBody struct {
- ServerURL string `json:"server_url"`
- }
- // HandleGetProjectRegistryGCRToken gets a GCR token for a registry
- func (app *App) HandleGetProjectRegistryGCRToken(w http.ResponseWriter, r *http.Request) {
- projID, err := strconv.ParseUint(chi.URLParam(r, "project_id"), 0, 64)
- if err != nil || projID == 0 {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- reqBody := &GCRTokenRequestBody{}
- // decode from JSON to form value
- if err := json.NewDecoder(r.Body).Decode(reqBody); err != nil {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- // list registries and find one that matches the region
- regs, err := app.Repo.Registry().ListRegistriesByProjectID(uint(projID))
- var token string
- var expiresAt *time.Time
- for _, reg := range regs {
- if reg.GCPIntegrationID != 0 && strings.Contains(reg.URL, reqBody.ServerURL) {
- _reg := registry.Registry(*reg)
- tokenCache, err := _reg.GetGCRToken(app.Repo)
- if err != nil {
- app.handleErrorDataRead(err, w)
- return
- }
- token = string(tokenCache.Token)
- expiresAt = &tokenCache.Expiry
- break
- }
- }
- resp := &RegTokenResponse{
- Token: token,
- ExpiresAt: expiresAt,
- }
- w.WriteHeader(http.StatusOK)
- if err := json.NewEncoder(w).Encode(resp); err != nil {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- }
- // HandleGetProjectRegistryDOCRToken gets a DOCR token for a registry
- func (app *App) HandleGetProjectRegistryDOCRToken(w http.ResponseWriter, r *http.Request) {
- projID, err := strconv.ParseUint(chi.URLParam(r, "project_id"), 0, 64)
- if err != nil || projID == 0 {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- reqBody := &GCRTokenRequestBody{}
- // decode from JSON to form value
- if err := json.NewDecoder(r.Body).Decode(reqBody); err != nil {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- // list registries and find one that matches the region
- regs, err := app.Repo.Registry().ListRegistriesByProjectID(uint(projID))
- var token string
- var expiresAt *time.Time
- for _, reg := range regs {
- if reg.DOIntegrationID != 0 && strings.Contains(reg.URL, reqBody.ServerURL) {
- oauthInt, err := app.Repo.OAuthIntegration().ReadOAuthIntegration(reg.DOIntegrationID)
- if err != nil {
- app.handleErrorDataRead(err, w)
- return
- }
- tok, expiry, err := oauth.GetAccessToken(oauthInt, app.DOConf, app.Repo)
- if err != nil {
- app.handleErrorDataRead(err, w)
- return
- }
- token = tok
- expiresAt = expiry
- break
- }
- }
- resp := &RegTokenResponse{
- Token: token,
- ExpiresAt: expiresAt,
- }
- w.WriteHeader(http.StatusOK)
- if err := json.NewEncoder(w).Encode(resp); err != nil {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- }
- // HandleUpdateProjectRegistry updates a registry
- func (app *App) HandleUpdateProjectRegistry(w http.ResponseWriter, r *http.Request) {
- projID, err := strconv.ParseUint(chi.URLParam(r, "project_id"), 0, 64)
- if err != nil || projID == 0 {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- registryID, err := strconv.ParseUint(chi.URLParam(r, "registry_id"), 0, 64)
- if err != nil || registryID == 0 {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- form := &forms.UpdateRegistryForm{
- ID: uint(registryID),
- }
- // decode from JSON to form value
- if err := json.NewDecoder(r.Body).Decode(form); err != nil {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- // validate the form
- if err := app.validator.Struct(form); err != nil {
- app.handleErrorFormValidation(err, ErrProjectValidateFields, w)
- return
- }
- // convert the form to a registry
- registry, err := form.ToRegistry(app.Repo.Registry())
- if err != nil {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- // handle write to the database
- registry, err = app.Repo.Registry().UpdateRegistry(registry)
- if err != nil {
- app.handleErrorDataWrite(err, w)
- return
- }
- w.WriteHeader(http.StatusOK)
- regExt := registry.Externalize()
- if err := json.NewEncoder(w).Encode(regExt); err != nil {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- }
- // HandleDeleteProjectRegistry handles the deletion of a Registry via the registry ID
- func (app *App) HandleDeleteProjectRegistry(w http.ResponseWriter, r *http.Request) {
- id, err := strconv.ParseUint(chi.URLParam(r, "registry_id"), 0, 64)
- if err != nil || id == 0 {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- reg, err := app.Repo.Registry().ReadRegistry(uint(id))
- if err != nil {
- app.handleErrorRead(err, ErrProjectDataRead, w)
- return
- }
- err = app.Repo.Registry().DeleteRegistry(reg)
- if err != nil {
- app.handleErrorRead(err, ErrProjectDataRead, w)
- return
- }
- w.WriteHeader(http.StatusOK)
- }
- // HandleListRepositories returns a list of repositories for a given registry
- func (app *App) HandleListRepositories(w http.ResponseWriter, r *http.Request) {
- regID, err := strconv.ParseUint(chi.URLParam(r, "registry_id"), 0, 64)
- if err != nil || regID == 0 {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- reg, err := app.Repo.Registry().ReadRegistry(uint(regID))
- if err != nil {
- app.handleErrorRead(err, ErrProjectDataRead, w)
- return
- }
- // cast to a registry from registry package
- _reg := registry.Registry(*reg)
- regAPI := &_reg
- repos, err := regAPI.ListRepositories(app.Repo, app.DOConf)
- if err != nil {
- app.handleErrorRead(err, ErrProjectDataRead, w)
- return
- }
- w.WriteHeader(http.StatusOK)
- if err := json.NewEncoder(w).Encode(repos); err != nil {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- }
- // HandleListImages retrieves a list of repo names
- func (app *App) HandleListImages(w http.ResponseWriter, r *http.Request) {
- regID, err := strconv.ParseUint(chi.URLParam(r, "registry_id"), 0, 64)
- if err != nil || regID == 0 {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- repoName := chi.URLParam(r, "*")
- reg, err := app.Repo.Registry().ReadRegistry(uint(regID))
- if err != nil {
- app.handleErrorRead(err, ErrProjectDataRead, w)
- return
- }
- // cast to a registry from registry package
- _reg := registry.Registry(*reg)
- regAPI := &_reg
- imgs, err := regAPI.ListImages(repoName, app.Repo, app.DOConf)
- if err != nil {
- app.handleErrorRead(err, ErrProjectDataRead, w)
- return
- }
- w.WriteHeader(http.StatusOK)
- if err := json.NewEncoder(w).Encode(imgs); err != nil {
- app.handleErrorFormDecoding(err, ErrProjectDecode, w)
- return
- }
- }
|