You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

AsIsFileService.java 5.0KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128
  1. /*
  2. * Copyright (C) 2009-2010, Google Inc.
  3. * and other copyright owners as documented in the project's IP log.
  4. *
  5. * This program and the accompanying materials are made available
  6. * under the terms of the Eclipse Distribution License v1.0 which
  7. * accompanies this distribution, is reproduced below, and is
  8. * available at http://www.eclipse.org/org/documents/edl-v10.php
  9. *
  10. * All rights reserved.
  11. *
  12. * Redistribution and use in source and binary forms, with or
  13. * without modification, are permitted provided that the following
  14. * conditions are met:
  15. *
  16. * - Redistributions of source code must retain the above copyright
  17. * notice, this list of conditions and the following disclaimer.
  18. *
  19. * - Redistributions in binary form must reproduce the above
  20. * copyright notice, this list of conditions and the following
  21. * disclaimer in the documentation and/or other materials provided
  22. * with the distribution.
  23. *
  24. * - Neither the name of the Eclipse Foundation, Inc. nor the
  25. * names of its contributors may be used to endorse or promote
  26. * products derived from this software without specific prior
  27. * written permission.
  28. *
  29. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND
  30. * CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES,
  31. * INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
  32. * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
  33. * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR
  34. * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
  35. * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
  36. * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
  37. * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
  38. * CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
  39. * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
  40. * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
  41. * ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
  42. */
  43. package org.eclipse.jgit.http.server.resolver;
  44. import javax.servlet.http.HttpServletRequest;
  45. import org.eclipse.jgit.http.server.GitServlet;
  46. import org.eclipse.jgit.lib.Config;
  47. import org.eclipse.jgit.lib.Config.SectionParser;
  48. import org.eclipse.jgit.lib.Repository;
  49. import org.eclipse.jgit.transport.resolver.ServiceNotAuthorizedException;
  50. import org.eclipse.jgit.transport.resolver.ServiceNotEnabledException;
  51. /**
  52. * Controls access to bare files in a repository.
  53. * <p>
  54. * Older HTTP clients which do not speak the smart HTTP variant of the Git
  55. * protocol fetch from a repository by directly getting its objects and pack
  56. * files. This class, along with the {@code http.getanyfile} per-repository
  57. * configuration setting, can be used by {@link GitServlet} to control whether
  58. * or not these older clients are permitted to read these direct files.
  59. */
  60. public class AsIsFileService {
  61. /** Always throws {@link ServiceNotEnabledException}. */
  62. public static final AsIsFileService DISABLED = new AsIsFileService() {
  63. @Override
  64. public void access(HttpServletRequest req, Repository db)
  65. throws ServiceNotEnabledException {
  66. throw new ServiceNotEnabledException();
  67. }
  68. };
  69. private static final SectionParser<ServiceConfig> CONFIG = new SectionParser<ServiceConfig>() {
  70. public ServiceConfig parse(final Config cfg) {
  71. return new ServiceConfig(cfg);
  72. }
  73. };
  74. private static class ServiceConfig {
  75. final boolean enabled;
  76. ServiceConfig(final Config cfg) {
  77. enabled = cfg.getBoolean("http", "getanyfile", true);
  78. }
  79. }
  80. /**
  81. * Determine if {@code http.getanyfile} is enabled in the configuration.
  82. *
  83. * @param db
  84. * the repository to check.
  85. * @return {@code false} if {@code http.getanyfile} was explicitly set to
  86. * {@code false} in the repository's configuration file; otherwise
  87. * {@code true}.
  88. */
  89. protected static boolean isEnabled(Repository db) {
  90. return db.getConfig().get(CONFIG).enabled;
  91. }
  92. /**
  93. * Determine if access to any bare file of the repository is allowed.
  94. * <p>
  95. * This method silently succeeds if the request is allowed, or fails by
  96. * throwing a checked exception if access should be denied.
  97. * <p>
  98. * The default implementation of this method checks {@code http.getanyfile},
  99. * throwing {@link ServiceNotEnabledException} if it was explicitly set to
  100. * {@code false}, and otherwise succeeding silently.
  101. *
  102. * @param req
  103. * current HTTP request, in case information from the request may
  104. * help determine the access request.
  105. * @param db
  106. * the repository the request would obtain a bare file from.
  107. * @throws ServiceNotEnabledException
  108. * bare file access is not allowed on the target repository, by
  109. * any user, for any reason.
  110. * @throws ServiceNotAuthorizedException
  111. * bare file access is not allowed for this HTTP request and
  112. * repository, such as due to a permission error.
  113. */
  114. public void access(HttpServletRequest req, Repository db)
  115. throws ServiceNotEnabledException, ServiceNotAuthorizedException {
  116. if (!isEnabled(db))
  117. throw new ServiceNotEnabledException();
  118. }
  119. }