Вы не можете выбрать более 25 тем Темы должны начинаться с буквы или цифры, могут содержать дефисы(-) и должны содержать не более 35 символов.

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473
  1. // Copyright 2014 The Gogs Authors. All rights reserved.
  2. // Copyright 2021 The Gitea Authors. All rights reserved.
  3. // Use of this source code is governed by a MIT-style
  4. // license that can be found in the LICENSE file.
  5. package install
  6. import (
  7. "fmt"
  8. "net/http"
  9. "os"
  10. "os/exec"
  11. "path/filepath"
  12. "strings"
  13. "time"
  14. "code.gitea.io/gitea/models"
  15. "code.gitea.io/gitea/modules/base"
  16. "code.gitea.io/gitea/modules/context"
  17. "code.gitea.io/gitea/modules/generate"
  18. "code.gitea.io/gitea/modules/graceful"
  19. "code.gitea.io/gitea/modules/log"
  20. "code.gitea.io/gitea/modules/setting"
  21. "code.gitea.io/gitea/modules/templates"
  22. "code.gitea.io/gitea/modules/translation"
  23. "code.gitea.io/gitea/modules/user"
  24. "code.gitea.io/gitea/modules/util"
  25. "code.gitea.io/gitea/modules/web"
  26. "code.gitea.io/gitea/modules/web/middleware"
  27. "code.gitea.io/gitea/services/forms"
  28. "gitea.com/go-chi/session"
  29. "gopkg.in/ini.v1"
  30. )
  31. const (
  32. // tplInstall template for installation page
  33. tplInstall base.TplName = "install"
  34. tplPostInstall base.TplName = "post-install"
  35. )
  36. // Init prepare for rendering installation page
  37. func Init(next http.Handler) http.Handler {
  38. var rnd = templates.HTMLRenderer()
  39. return http.HandlerFunc(func(resp http.ResponseWriter, req *http.Request) {
  40. if setting.InstallLock {
  41. resp.Header().Add("Refresh", "1; url="+setting.AppURL+"user/login")
  42. _ = rnd.HTML(resp, 200, string(tplPostInstall), nil)
  43. return
  44. }
  45. var locale = middleware.Locale(resp, req)
  46. var startTime = time.Now()
  47. var ctx = context.Context{
  48. Resp: context.NewResponse(resp),
  49. Flash: &middleware.Flash{},
  50. Locale: locale,
  51. Render: rnd,
  52. Session: session.GetSession(req),
  53. Data: map[string]interface{}{
  54. "Title": locale.Tr("install.install"),
  55. "PageIsInstall": true,
  56. "DbOptions": setting.SupportedDatabases,
  57. "i18n": locale,
  58. "Language": locale.Language(),
  59. "Lang": locale.Language(),
  60. "AllLangs": translation.AllLangs(),
  61. "CurrentURL": setting.AppSubURL + req.URL.RequestURI(),
  62. "PageStartTime": startTime,
  63. "TmplLoadTimes": func() string {
  64. return time.Since(startTime).String()
  65. },
  66. "PasswordHashAlgorithms": models.AvailableHashAlgorithms,
  67. },
  68. }
  69. for _, lang := range translation.AllLangs() {
  70. if lang.Lang == locale.Language() {
  71. ctx.Data["LangName"] = lang.Name
  72. break
  73. }
  74. }
  75. ctx.Req = context.WithContext(req, &ctx)
  76. next.ServeHTTP(resp, ctx.Req)
  77. })
  78. }
  79. // Install render installation page
  80. func Install(ctx *context.Context) {
  81. form := forms.InstallForm{}
  82. // Database settings
  83. form.DbHost = setting.Database.Host
  84. form.DbUser = setting.Database.User
  85. form.DbPasswd = setting.Database.Passwd
  86. form.DbName = setting.Database.Name
  87. form.DbPath = setting.Database.Path
  88. form.DbSchema = setting.Database.Schema
  89. form.Charset = setting.Database.Charset
  90. var curDBOption = "MySQL"
  91. switch setting.Database.Type {
  92. case "postgres":
  93. curDBOption = "PostgreSQL"
  94. case "mssql":
  95. curDBOption = "MSSQL"
  96. case "sqlite3":
  97. if setting.EnableSQLite3 {
  98. curDBOption = "SQLite3"
  99. }
  100. }
  101. ctx.Data["CurDbOption"] = curDBOption
  102. // Application general settings
  103. form.AppName = setting.AppName
  104. form.RepoRootPath = setting.RepoRootPath
  105. form.LFSRootPath = setting.LFS.Path
  106. // Note(unknown): it's hard for Windows users change a running user,
  107. // so just use current one if config says default.
  108. if setting.IsWindows && setting.RunUser == "git" {
  109. form.RunUser = user.CurrentUsername()
  110. } else {
  111. form.RunUser = setting.RunUser
  112. }
  113. form.Domain = setting.Domain
  114. form.SSHPort = setting.SSH.Port
  115. form.HTTPPort = setting.HTTPPort
  116. form.AppURL = setting.AppURL
  117. form.LogRootPath = setting.LogRootPath
  118. // E-mail service settings
  119. if setting.MailService != nil {
  120. form.SMTPHost = setting.MailService.Host
  121. form.SMTPFrom = setting.MailService.From
  122. form.SMTPUser = setting.MailService.User
  123. }
  124. form.RegisterConfirm = setting.Service.RegisterEmailConfirm
  125. form.MailNotify = setting.Service.EnableNotifyMail
  126. // Server and other services settings
  127. form.OfflineMode = setting.OfflineMode
  128. form.DisableGravatar = setting.DisableGravatar
  129. form.EnableFederatedAvatar = setting.EnableFederatedAvatar
  130. form.EnableOpenIDSignIn = setting.Service.EnableOpenIDSignIn
  131. form.EnableOpenIDSignUp = setting.Service.EnableOpenIDSignUp
  132. form.DisableRegistration = setting.Service.DisableRegistration
  133. form.AllowOnlyExternalRegistration = setting.Service.AllowOnlyExternalRegistration
  134. form.EnableCaptcha = setting.Service.EnableCaptcha
  135. form.RequireSignInView = setting.Service.RequireSignInView
  136. form.DefaultKeepEmailPrivate = setting.Service.DefaultKeepEmailPrivate
  137. form.DefaultAllowCreateOrganization = setting.Service.DefaultAllowCreateOrganization
  138. form.DefaultEnableTimetracking = setting.Service.DefaultEnableTimetracking
  139. form.NoReplyAddress = setting.Service.NoReplyAddress
  140. form.PasswordAlgorithm = setting.PasswordHashAlgo
  141. middleware.AssignForm(form, ctx.Data)
  142. ctx.HTML(http.StatusOK, tplInstall)
  143. }
  144. // SubmitInstall response for submit install items
  145. func SubmitInstall(ctx *context.Context) {
  146. form := *web.GetForm(ctx).(*forms.InstallForm)
  147. var err error
  148. ctx.Data["CurDbOption"] = form.DbType
  149. if ctx.HasError() {
  150. if ctx.HasValue("Err_SMTPUser") {
  151. ctx.Data["Err_SMTP"] = true
  152. }
  153. if ctx.HasValue("Err_AdminName") ||
  154. ctx.HasValue("Err_AdminPasswd") ||
  155. ctx.HasValue("Err_AdminEmail") {
  156. ctx.Data["Err_Admin"] = true
  157. }
  158. ctx.HTML(http.StatusOK, tplInstall)
  159. return
  160. }
  161. if _, err = exec.LookPath("git"); err != nil {
  162. ctx.RenderWithErr(ctx.Tr("install.test_git_failed", err), tplInstall, &form)
  163. return
  164. }
  165. // Pass basic check, now test configuration.
  166. // Test database setting.
  167. setting.Database.Type = setting.GetDBTypeByName(form.DbType)
  168. setting.Database.Host = form.DbHost
  169. setting.Database.User = form.DbUser
  170. setting.Database.Passwd = form.DbPasswd
  171. setting.Database.Name = form.DbName
  172. setting.Database.Schema = form.DbSchema
  173. setting.Database.SSLMode = form.SSLMode
  174. setting.Database.Charset = form.Charset
  175. setting.Database.Path = form.DbPath
  176. setting.PasswordHashAlgo = form.PasswordAlgorithm
  177. if (setting.Database.Type == "sqlite3") &&
  178. len(setting.Database.Path) == 0 {
  179. ctx.Data["Err_DbPath"] = true
  180. ctx.RenderWithErr(ctx.Tr("install.err_empty_db_path"), tplInstall, &form)
  181. return
  182. }
  183. // Set test engine.
  184. if err = models.NewTestEngine(); err != nil {
  185. if strings.Contains(err.Error(), `Unknown database type: sqlite3`) {
  186. ctx.Data["Err_DbType"] = true
  187. ctx.RenderWithErr(ctx.Tr("install.sqlite3_not_available", "https://docs.gitea.io/en-us/install-from-binary/"), tplInstall, &form)
  188. } else {
  189. ctx.Data["Err_DbSetting"] = true
  190. ctx.RenderWithErr(ctx.Tr("install.invalid_db_setting", err), tplInstall, &form)
  191. }
  192. return
  193. }
  194. // Test repository root path.
  195. form.RepoRootPath = strings.ReplaceAll(form.RepoRootPath, "\\", "/")
  196. if err = os.MkdirAll(form.RepoRootPath, os.ModePerm); err != nil {
  197. ctx.Data["Err_RepoRootPath"] = true
  198. ctx.RenderWithErr(ctx.Tr("install.invalid_repo_path", err), tplInstall, &form)
  199. return
  200. }
  201. // Test LFS root path if not empty, empty meaning disable LFS
  202. if form.LFSRootPath != "" {
  203. form.LFSRootPath = strings.ReplaceAll(form.LFSRootPath, "\\", "/")
  204. if err := os.MkdirAll(form.LFSRootPath, os.ModePerm); err != nil {
  205. ctx.Data["Err_LFSRootPath"] = true
  206. ctx.RenderWithErr(ctx.Tr("install.invalid_lfs_path", err), tplInstall, &form)
  207. return
  208. }
  209. }
  210. // Test log root path.
  211. form.LogRootPath = strings.ReplaceAll(form.LogRootPath, "\\", "/")
  212. if err = os.MkdirAll(form.LogRootPath, os.ModePerm); err != nil {
  213. ctx.Data["Err_LogRootPath"] = true
  214. ctx.RenderWithErr(ctx.Tr("install.invalid_log_root_path", err), tplInstall, &form)
  215. return
  216. }
  217. currentUser, match := setting.IsRunUserMatchCurrentUser(form.RunUser)
  218. if !match {
  219. ctx.Data["Err_RunUser"] = true
  220. ctx.RenderWithErr(ctx.Tr("install.run_user_not_match", form.RunUser, currentUser), tplInstall, &form)
  221. return
  222. }
  223. // Check logic loophole between disable self-registration and no admin account.
  224. if form.DisableRegistration && len(form.AdminName) == 0 {
  225. ctx.Data["Err_Services"] = true
  226. ctx.Data["Err_Admin"] = true
  227. ctx.RenderWithErr(ctx.Tr("install.no_admin_and_disable_registration"), tplInstall, form)
  228. return
  229. }
  230. // Check admin user creation
  231. if len(form.AdminName) > 0 {
  232. // Ensure AdminName is valid
  233. if err := models.IsUsableUsername(form.AdminName); err != nil {
  234. ctx.Data["Err_Admin"] = true
  235. ctx.Data["Err_AdminName"] = true
  236. if models.IsErrNameReserved(err) {
  237. ctx.RenderWithErr(ctx.Tr("install.err_admin_name_is_reserved"), tplInstall, form)
  238. return
  239. } else if models.IsErrNamePatternNotAllowed(err) {
  240. ctx.RenderWithErr(ctx.Tr("install.err_admin_name_pattern_not_allowed"), tplInstall, form)
  241. return
  242. }
  243. ctx.RenderWithErr(ctx.Tr("install.err_admin_name_is_invalid"), tplInstall, form)
  244. return
  245. }
  246. // Check Admin email
  247. if len(form.AdminEmail) == 0 {
  248. ctx.Data["Err_Admin"] = true
  249. ctx.Data["Err_AdminEmail"] = true
  250. ctx.RenderWithErr(ctx.Tr("install.err_empty_admin_email"), tplInstall, form)
  251. return
  252. }
  253. // Check admin password.
  254. if len(form.AdminPasswd) == 0 {
  255. ctx.Data["Err_Admin"] = true
  256. ctx.Data["Err_AdminPasswd"] = true
  257. ctx.RenderWithErr(ctx.Tr("install.err_empty_admin_password"), tplInstall, form)
  258. return
  259. }
  260. if form.AdminPasswd != form.AdminConfirmPasswd {
  261. ctx.Data["Err_Admin"] = true
  262. ctx.Data["Err_AdminPasswd"] = true
  263. ctx.RenderWithErr(ctx.Tr("form.password_not_match"), tplInstall, form)
  264. return
  265. }
  266. }
  267. if form.AppURL[len(form.AppURL)-1] != '/' {
  268. form.AppURL += "/"
  269. }
  270. // Save settings.
  271. cfg := ini.Empty()
  272. isFile, err := util.IsFile(setting.CustomConf)
  273. if err != nil {
  274. log.Error("Unable to check if %s is a file. Error: %v", setting.CustomConf, err)
  275. }
  276. if isFile {
  277. // Keeps custom settings if there is already something.
  278. if err = cfg.Append(setting.CustomConf); err != nil {
  279. log.Error("Failed to load custom conf '%s': %v", setting.CustomConf, err)
  280. }
  281. }
  282. cfg.Section("database").Key("DB_TYPE").SetValue(setting.Database.Type)
  283. cfg.Section("database").Key("HOST").SetValue(setting.Database.Host)
  284. cfg.Section("database").Key("NAME").SetValue(setting.Database.Name)
  285. cfg.Section("database").Key("USER").SetValue(setting.Database.User)
  286. cfg.Section("database").Key("PASSWD").SetValue(setting.Database.Passwd)
  287. cfg.Section("database").Key("SCHEMA").SetValue(setting.Database.Schema)
  288. cfg.Section("database").Key("SSL_MODE").SetValue(setting.Database.SSLMode)
  289. cfg.Section("database").Key("CHARSET").SetValue(setting.Database.Charset)
  290. cfg.Section("database").Key("PATH").SetValue(setting.Database.Path)
  291. cfg.Section("database").Key("LOG_SQL").SetValue("false") // LOG_SQL is rarely helpful
  292. cfg.Section("").Key("APP_NAME").SetValue(form.AppName)
  293. cfg.Section("repository").Key("ROOT").SetValue(form.RepoRootPath)
  294. cfg.Section("").Key("RUN_USER").SetValue(form.RunUser)
  295. cfg.Section("server").Key("SSH_DOMAIN").SetValue(form.Domain)
  296. cfg.Section("server").Key("DOMAIN").SetValue(form.Domain)
  297. cfg.Section("server").Key("HTTP_PORT").SetValue(form.HTTPPort)
  298. cfg.Section("server").Key("ROOT_URL").SetValue(form.AppURL)
  299. if form.SSHPort == 0 {
  300. cfg.Section("server").Key("DISABLE_SSH").SetValue("true")
  301. } else {
  302. cfg.Section("server").Key("DISABLE_SSH").SetValue("false")
  303. cfg.Section("server").Key("SSH_PORT").SetValue(fmt.Sprint(form.SSHPort))
  304. }
  305. if form.LFSRootPath != "" {
  306. cfg.Section("server").Key("LFS_START_SERVER").SetValue("true")
  307. cfg.Section("server").Key("LFS_CONTENT_PATH").SetValue(form.LFSRootPath)
  308. var secretKey string
  309. if secretKey, err = generate.NewJwtSecret(); err != nil {
  310. ctx.RenderWithErr(ctx.Tr("install.lfs_jwt_secret_failed", err), tplInstall, &form)
  311. return
  312. }
  313. cfg.Section("server").Key("LFS_JWT_SECRET").SetValue(secretKey)
  314. } else {
  315. cfg.Section("server").Key("LFS_START_SERVER").SetValue("false")
  316. }
  317. if len(strings.TrimSpace(form.SMTPHost)) > 0 {
  318. cfg.Section("mailer").Key("ENABLED").SetValue("true")
  319. cfg.Section("mailer").Key("HOST").SetValue(form.SMTPHost)
  320. cfg.Section("mailer").Key("FROM").SetValue(form.SMTPFrom)
  321. cfg.Section("mailer").Key("USER").SetValue(form.SMTPUser)
  322. cfg.Section("mailer").Key("PASSWD").SetValue(form.SMTPPasswd)
  323. } else {
  324. cfg.Section("mailer").Key("ENABLED").SetValue("false")
  325. }
  326. cfg.Section("service").Key("REGISTER_EMAIL_CONFIRM").SetValue(fmt.Sprint(form.RegisterConfirm))
  327. cfg.Section("service").Key("ENABLE_NOTIFY_MAIL").SetValue(fmt.Sprint(form.MailNotify))
  328. cfg.Section("server").Key("OFFLINE_MODE").SetValue(fmt.Sprint(form.OfflineMode))
  329. cfg.Section("picture").Key("DISABLE_GRAVATAR").SetValue(fmt.Sprint(form.DisableGravatar))
  330. cfg.Section("picture").Key("ENABLE_FEDERATED_AVATAR").SetValue(fmt.Sprint(form.EnableFederatedAvatar))
  331. cfg.Section("openid").Key("ENABLE_OPENID_SIGNIN").SetValue(fmt.Sprint(form.EnableOpenIDSignIn))
  332. cfg.Section("openid").Key("ENABLE_OPENID_SIGNUP").SetValue(fmt.Sprint(form.EnableOpenIDSignUp))
  333. cfg.Section("service").Key("DISABLE_REGISTRATION").SetValue(fmt.Sprint(form.DisableRegistration))
  334. cfg.Section("service").Key("ALLOW_ONLY_EXTERNAL_REGISTRATION").SetValue(fmt.Sprint(form.AllowOnlyExternalRegistration))
  335. cfg.Section("service").Key("ENABLE_CAPTCHA").SetValue(fmt.Sprint(form.EnableCaptcha))
  336. cfg.Section("service").Key("REQUIRE_SIGNIN_VIEW").SetValue(fmt.Sprint(form.RequireSignInView))
  337. cfg.Section("service").Key("DEFAULT_KEEP_EMAIL_PRIVATE").SetValue(fmt.Sprint(form.DefaultKeepEmailPrivate))
  338. cfg.Section("service").Key("DEFAULT_ALLOW_CREATE_ORGANIZATION").SetValue(fmt.Sprint(form.DefaultAllowCreateOrganization))
  339. cfg.Section("service").Key("DEFAULT_ENABLE_TIMETRACKING").SetValue(fmt.Sprint(form.DefaultEnableTimetracking))
  340. cfg.Section("service").Key("NO_REPLY_ADDRESS").SetValue(fmt.Sprint(form.NoReplyAddress))
  341. cfg.Section("").Key("RUN_MODE").SetValue("prod")
  342. cfg.Section("session").Key("PROVIDER").SetValue("file")
  343. cfg.Section("log").Key("MODE").SetValue("console")
  344. cfg.Section("log").Key("LEVEL").SetValue(setting.LogLevel.String())
  345. cfg.Section("log").Key("ROOT_PATH").SetValue(form.LogRootPath)
  346. cfg.Section("log").Key("ROUTER").SetValue("console")
  347. cfg.Section("security").Key("INSTALL_LOCK").SetValue("true")
  348. var secretKey string
  349. if secretKey, err = generate.NewSecretKey(); err != nil {
  350. ctx.RenderWithErr(ctx.Tr("install.secret_key_failed", err), tplInstall, &form)
  351. return
  352. }
  353. cfg.Section("security").Key("SECRET_KEY").SetValue(secretKey)
  354. if len(form.PasswordAlgorithm) > 0 {
  355. cfg.Section("security").Key("PASSWORD_HASH_ALGO").SetValue(form.PasswordAlgorithm)
  356. }
  357. err = os.MkdirAll(filepath.Dir(setting.CustomConf), os.ModePerm)
  358. if err != nil {
  359. ctx.RenderWithErr(ctx.Tr("install.save_config_failed", err), tplInstall, &form)
  360. return
  361. }
  362. if err = cfg.SaveTo(setting.CustomConf); err != nil {
  363. ctx.RenderWithErr(ctx.Tr("install.save_config_failed", err), tplInstall, &form)
  364. return
  365. }
  366. // Re-read settings
  367. ReloadSettings(ctx)
  368. // Create admin account
  369. if len(form.AdminName) > 0 {
  370. u := &models.User{
  371. Name: form.AdminName,
  372. Email: form.AdminEmail,
  373. Passwd: form.AdminPasswd,
  374. IsAdmin: true,
  375. IsActive: true,
  376. }
  377. if err = models.CreateUser(u); err != nil {
  378. if !models.IsErrUserAlreadyExist(err) {
  379. setting.InstallLock = false
  380. ctx.Data["Err_AdminName"] = true
  381. ctx.Data["Err_AdminEmail"] = true
  382. ctx.RenderWithErr(ctx.Tr("install.invalid_admin_setting", err), tplInstall, &form)
  383. return
  384. }
  385. log.Info("Admin account already exist")
  386. u, _ = models.GetUserByName(u.Name)
  387. }
  388. days := 86400 * setting.LogInRememberDays
  389. ctx.SetCookie(setting.CookieUserName, u.Name, days)
  390. ctx.SetSuperSecureCookie(base.EncodeMD5(u.Rands+u.Passwd),
  391. setting.CookieRememberName, u.Name, days)
  392. // Auto-login for admin
  393. if err = ctx.Session.Set("uid", u.ID); err != nil {
  394. ctx.RenderWithErr(ctx.Tr("install.save_config_failed", err), tplInstall, &form)
  395. return
  396. }
  397. if err = ctx.Session.Set("uname", u.Name); err != nil {
  398. ctx.RenderWithErr(ctx.Tr("install.save_config_failed", err), tplInstall, &form)
  399. return
  400. }
  401. if err = ctx.Session.Release(); err != nil {
  402. ctx.RenderWithErr(ctx.Tr("install.save_config_failed", err), tplInstall, &form)
  403. return
  404. }
  405. }
  406. log.Info("First-time run install finished!")
  407. ctx.Flash.Success(ctx.Tr("install.install_success"))
  408. ctx.Header().Add("Refresh", "1; url="+setting.AppURL+"user/login")
  409. ctx.HTML(http.StatusOK, tplPostInstall)
  410. // Now get the http.Server from this request and shut it down
  411. // NB: This is not our hammerable graceful shutdown this is http.Server.Shutdown
  412. srv := ctx.Value(http.ServerContextKey).(*http.Server)
  413. go func() {
  414. if err := srv.Shutdown(graceful.GetManager().HammerContext()); err != nil {
  415. log.Error("Unable to shutdown the install server! Error: %v", err)
  416. }
  417. }()
  418. }