You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

AsIsFileService.java 4.8KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123
  1. /*
  2. * Copyright (C) 2009-2010, Google Inc.
  3. * and other copyright owners as documented in the project's IP log.
  4. *
  5. * This program and the accompanying materials are made available
  6. * under the terms of the Eclipse Distribution License v1.0 which
  7. * accompanies this distribution, is reproduced below, and is
  8. * available at http://www.eclipse.org/org/documents/edl-v10.php
  9. *
  10. * All rights reserved.
  11. *
  12. * Redistribution and use in source and binary forms, with or
  13. * without modification, are permitted provided that the following
  14. * conditions are met:
  15. *
  16. * - Redistributions of source code must retain the above copyright
  17. * notice, this list of conditions and the following disclaimer.
  18. *
  19. * - Redistributions in binary form must reproduce the above
  20. * copyright notice, this list of conditions and the following
  21. * disclaimer in the documentation and/or other materials provided
  22. * with the distribution.
  23. *
  24. * - Neither the name of the Eclipse Foundation, Inc. nor the
  25. * names of its contributors may be used to endorse or promote
  26. * products derived from this software without specific prior
  27. * written permission.
  28. *
  29. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND
  30. * CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES,
  31. * INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
  32. * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
  33. * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR
  34. * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
  35. * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
  36. * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
  37. * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
  38. * CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
  39. * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
  40. * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
  41. * ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
  42. */
  43. package org.eclipse.jgit.http.server.resolver;
  44. import javax.servlet.http.HttpServletRequest;
  45. import org.eclipse.jgit.lib.Config;
  46. import org.eclipse.jgit.lib.Repository;
  47. import org.eclipse.jgit.transport.resolver.ServiceNotAuthorizedException;
  48. import org.eclipse.jgit.transport.resolver.ServiceNotEnabledException;
  49. /**
  50. * Controls access to bare files in a repository.
  51. * <p>
  52. * Older HTTP clients which do not speak the smart HTTP variant of the Git
  53. * protocol fetch from a repository by directly getting its objects and pack
  54. * files. This class, along with the {@code http.getanyfile} per-repository
  55. * configuration setting, can be used by
  56. * {@link org.eclipse.jgit.http.server.GitServlet} to control whether or not
  57. * these older clients are permitted to read these direct files.
  58. */
  59. public class AsIsFileService {
  60. /** Always throws {@link ServiceNotEnabledException}. */
  61. public static final AsIsFileService DISABLED = new AsIsFileService() {
  62. @Override
  63. public void access(HttpServletRequest req, Repository db)
  64. throws ServiceNotEnabledException {
  65. throw new ServiceNotEnabledException();
  66. }
  67. };
  68. private static class ServiceConfig {
  69. final boolean enabled;
  70. ServiceConfig(Config cfg) {
  71. enabled = cfg.getBoolean("http", "getanyfile", true);
  72. }
  73. }
  74. /**
  75. * Determine if {@code http.getanyfile} is enabled in the configuration.
  76. *
  77. * @param db
  78. * the repository to check.
  79. * @return {@code false} if {@code http.getanyfile} was explicitly set to
  80. * {@code false} in the repository's configuration file; otherwise
  81. * {@code true}.
  82. */
  83. protected static boolean isEnabled(Repository db) {
  84. return db.getConfig().get(ServiceConfig::new).enabled;
  85. }
  86. /**
  87. * Determine if access to any bare file of the repository is allowed.
  88. * <p>
  89. * This method silently succeeds if the request is allowed, or fails by
  90. * throwing a checked exception if access should be denied.
  91. * <p>
  92. * The default implementation of this method checks {@code http.getanyfile},
  93. * throwing
  94. * {@link org.eclipse.jgit.transport.resolver.ServiceNotEnabledException} if
  95. * it was explicitly set to {@code false}, and otherwise succeeding
  96. * silently.
  97. *
  98. * @param req
  99. * current HTTP request, in case information from the request may
  100. * help determine the access request.
  101. * @param db
  102. * the repository the request would obtain a bare file from.
  103. * @throws ServiceNotEnabledException
  104. * bare file access is not allowed on the target repository, by
  105. * any user, for any reason.
  106. * @throws ServiceNotAuthorizedException
  107. * bare file access is not allowed for this HTTP request and
  108. * repository, such as due to a permission error.
  109. */
  110. public void access(HttpServletRequest req, Repository db)
  111. throws ServiceNotEnabledException, ServiceNotAuthorizedException {
  112. if (!isEnabled(db))
  113. throw new ServiceNotEnabledException();
  114. }
  115. }