20 #include <ripple/app/main/Application.h>
21 #include <ripple/app/misc/NetworkOPs.h>
22 #include <ripple/basics/Log.h>
23 #include <ripple/basics/base64.h>
24 #include <ripple/basics/contract.h>
25 #include <ripple/basics/make_SSLContext.h>
26 #include <ripple/beast/net/IPAddressConversion.h>
27 #include <ripple/beast/rfc2616.h>
28 #include <ripple/core/JobQueue.h>
29 #include <ripple/json/json_reader.h>
30 #include <ripple/json/to_string.h>
31 #include <ripple/net/RPCErr.h>
32 #include <ripple/overlay/Overlay.h>
33 #include <ripple/resource/Fees.h>
34 #include <ripple/resource/ResourceManager.h>
35 #include <ripple/rpc/RPCHandler.h>
36 #include <ripple/rpc/Role.h>
37 #include <ripple/rpc/ServerHandler.h>
38 #include <ripple/rpc/impl/RPCHelpers.h>
39 #include <ripple/rpc/impl/ServerHandlerImp.h>
40 #include <ripple/rpc/impl/Tuning.h>
41 #include <ripple/rpc/json_body.h>
42 #include <ripple/server/Server.h>
43 #include <ripple/server/SimpleWriter.h>
44 #include <ripple/server/impl/JSONRPCUtil.h>
45 #include <boost/algorithm/string.hpp>
46 #include <boost/beast/http/fields.hpp>
47 #include <boost/beast/http/string_body.hpp>
48 #include <boost/optional.hpp>
49 #include <boost/regex.hpp>
50 #include <boost/type_traits.hpp>
59 return request.version() >= 11 && request.target() ==
"/" &&
60 request.body().size() == 0 &&
61 request.method() == boost::beast::http::verb::get;
67 boost::beast::http::status status)
69 using namespace boost::beast::http;
71 response<string_body> msg;
72 msg.version(request.version());
75 msg.insert(
"Content-Type",
"text/html");
76 msg.insert(
"Connection",
"close");
77 msg.body() =
"Invalid protocol.";
78 msg.prepare_payload();
79 handoff.
response = std::make_shared<SimpleWriter>(msg);
90 auto const it = h.
find(
"authorization");
91 if ((it == h.
end()) || (it->second.substr(0, 6) !=
"Basic "))
94 boost::trim(strUserPass64);
96 std::string::size_type nColon = strUserPass.
find(
":");
97 if (nColon == std::string::npos)
101 return strUser == port.
user && strPassword == port.
password;
107 boost::asio::io_service& io_service,
114 , m_resourceManager(resourceManager)
115 , m_journal(app_.journal(
"Server"))
116 , m_networkOPs(networkOPs)
117 , m_server(
make_Server(*this, io_service, app_.journal(
"Server")))
118 , m_jobQueue(jobQueue)
120 auto const& group(cm.
group(
"rpc"));
151 boost::asio::ip::tcp::endpoint endpoint)
160 << session.
port().
name <<
" is full; dropping " << endpoint;
172 boost::asio::ip::tcp::endpoint
const& remote_address)
174 using namespace boost::beast;
177 p.
count(
"ws") > 0 || p.count(
"ws2") > 0 || p.count(
"wss") > 0 ||
178 p.count(
"wss2") > 0};
180 if (websocket::is_upgrade(request))
193 <<
"Exception upgrading websocket: " << e.
what() <<
"\n";
195 request, http::status::internal_server_error);
199 auto const beast_remote_address =
203 beast_remote_address,
208 beast_remote_address,
211 is->forwarded_for());
212 ws->appDefined = std::move(is);
216 handoff.
moved =
true;
220 if (bundle && p.count(
"peer") > 0)
222 std::move(bundle), std::move(request), remote_address);
234 return [&](boost::beast::string_view
const& b) {
235 session.
write(b.data(), b.size());
243 for (
auto const& e : h)
245 auto key(e.name_string().to_string());
247 return std::tolower(static_cast<unsigned char>(kc));
249 c[key] = e.value().to_string();
254 template <
class ConstBufferSequence>
258 using boost::asio::buffer_cast;
259 using boost::asio::buffer_size;
262 for (
auto const& b : bs)
263 s.
append(buffer_cast<char const*>(b), buffer_size(b));
294 if (postResult ==
nullptr)
299 "Service Unavailable",
302 detachedSession->close(
true);
313 auto const size = boost::asio::buffer_size(buffers);
318 jvResult[jss::type] = jss::error;
319 jvResult[jss::error] =
"jsonInvalid";
321 boost::beast::multi_buffer sb;
322 Json::stream(jvResult, [&sb](
auto const p,
auto const n) {
323 sb.commit(boost::asio::buffer_copy(
324 sb.prepare(n), boost::asio::buffer(p, n)));
326 JLOG(
m_journal.
trace()) <<
"Websocket sending '" << jvResult <<
"'";
338 [
this, session, jv = std::move(jv)](
342 auto const n = s.length();
343 boost::beast::multi_buffer sb(n);
344 sb.commit(boost::asio::buffer_copy(
345 sb.prepare(n), boost::asio::buffer(s.c_str(), n)));
350 if (postResult ==
nullptr)
353 session->close({boost::beast::websocket::going_away,
"Shutting Down"});
378 auto is = std::static_pointer_cast<WSInfoSub>(session->appDefined);
379 if (is->getConsumer().disconnect())
382 {boost::beast::websocket::policy_error,
"threshold exceeded"});
401 jr[jss::type] = jss::response;
402 jr[jss::status] = jss::error;
404 ? jss::invalid_API_version
405 : jss::missingCommand;
406 jr[jss::request] = jv;
408 jr[jss::id] = jv[jss::id];
410 jr[jss::jsonrpc] = jv[jss::jsonrpc];
412 jr[jss::ripplerpc] = jv[jss::ripplerpc];
414 jr[jss::api_version] = jv[jss::api_version];
449 {is->user(), is->forwarded_for()}};
458 <<
"Exception while processing WS: " << ex.
what() <<
"\n"
462 is->getConsumer().charge(loadType);
463 if (is->getConsumer().warn())
464 jr[jss::warning] = jss::load;
471 if (jr[jss::result].isMember(jss::error))
473 jr = jr[jss::result];
474 jr[jss::status] = jss::error;
480 if (rq.isMember(jss::passphrase.c_str()))
481 rq[jss::passphrase.c_str()] =
"<masked>";
482 if (rq.isMember(jss::secret.c_str()))
483 rq[jss::secret.c_str()] =
"<masked>";
484 if (rq.isMember(jss::seed.c_str()))
485 rq[jss::seed.c_str()] =
"<masked>";
486 if (rq.isMember(jss::seed_hex.c_str()))
487 rq[jss::seed_hex.c_str()] =
"<masked>";
490 jr[jss::request] = rq;
494 if (jr[jss::result].isMember(
"forwarded") &&
495 jr[jss::result][
"forwarded"])
496 jr = jr[jss::result];
497 jr[jss::status] = jss::success;
501 jr[jss::id] = jv[jss::id];
503 jr[jss::jsonrpc] = jv[jss::jsonrpc];
505 jr[jss::ripplerpc] = jv[jss::ripplerpc];
507 jr[jss::api_version] = jv[jss::api_version];
509 jr[jss::type] = jss::response;
522 session->remoteAddress().at_port(0),
527 auto const iter = session->request().find(
"X-User");
528 if (iter != session->request().end())
529 return iter->value();
530 return boost::beast::string_view{};
536 session->close(
true);
544 sub[
"message"] = std::move(message);
563 boost::string_view user)
571 !reader.
parse(request, jsonOrig) || !jsonOrig ||
585 if (jsonOrig.
isMember(jss::method) && jsonOrig[jss::method] ==
"batch")
588 if (!jsonOrig.
isMember(jss::params) || !jsonOrig[jss::params].
isArray())
590 HTTPReply(400,
"Malformed batch request", output, rpcJ);
593 size = jsonOrig[jss::params].
size();
598 for (
unsigned i = 0; i < size; ++i)
601 batch ? jsonOrig[jss::params][i] : jsonOrig;
606 r[jss::request] = jsonRPC;
615 jsonRPC[jss::params].
size() > 0 &&
616 jsonRPC[jss::params][0u].
isObject())
632 HTTPReply(400, jss::invalid_API_version.c_str(), output, rpcJ);
636 r[jss::request] = jsonRPC;
651 jsonRPC[jss::params].
size() > 0 &&
680 HTTPReply(503,
"Server is overloaded", output, rpcJ);
696 HTTPReply(403,
"Forbidden", output, rpcJ);
705 if (!jsonRPC.
isMember(jss::method) || jsonRPC[jss::method].
isNull())
710 HTTPReply(400,
"Null method", output, rpcJ);
725 HTTPReply(400,
"method is not string", output, rpcJ);
736 if (strMethod.
empty())
741 HTTPReply(400,
"method is empty", output, rpcJ);
760 params = jsonRPC[jss::params];
767 HTTPReply(400,
"params unparseable", output, rpcJ);
772 params = std::move(params[0u]);
776 HTTPReply(400,
"params unparseable", output, rpcJ);
787 if (params.
isMember(jss::ripplerpc))
789 if (!params[jss::ripplerpc].isString())
794 HTTPReply(400,
"ripplerpc is not a string", output, rpcJ);
804 ripplerpc = params[jss::ripplerpc].
asString();
820 params[jss::command] = strMethod;
822 <<
"doRpcCommand:" << strMethod <<
":" << params;
843 result[jss::warning] = jss::load;
846 if (ripplerpc >=
"2.0")
850 result[jss::status] = jss::error;
851 result[
"code"] = result[jss::error_code];
852 result[
"message"] = result[jss::error_message];
855 <<
": " << result[jss::error_message];
856 r[jss::error] = std::move(result);
860 result[jss::status] = jss::success;
861 r[jss::result] = std::move(result);
874 if (rq.isMember(jss::passphrase.c_str()))
875 rq[jss::passphrase.c_str()] =
"<masked>";
876 if (rq.isMember(jss::secret.c_str()))
877 rq[jss::secret.c_str()] =
"<masked>";
878 if (rq.isMember(jss::seed.c_str()))
879 rq[jss::seed.c_str()] =
"<masked>";
880 if (rq.isMember(jss::seed_hex.c_str()))
881 rq[jss::seed_hex.c_str()] =
"<masked>";
884 result[jss::status] = jss::error;
885 result[jss::request] = rq;
888 <<
": " << result[jss::error_message];
892 result[jss::status] = jss::success;
894 r[jss::result] = std::move(result);
897 if (params.isMember(jss::jsonrpc))
898 r[jss::jsonrpc] = params[jss::jsonrpc];
899 if (params.isMember(jss::ripplerpc))
900 r[jss::ripplerpc] = params[jss::ripplerpc];
901 if (params.isMember(jss::id))
902 r[jss::id] = params[jss::id];
904 reply.
append(std::move(r));
906 reply = std::move(r);
910 rpc_time_.
notify(std::chrono::duration_cast<std::chrono::milliseconds>(
919 static const int maxSize = 10000;
920 if (response.size() <= maxSize)
921 stream <<
"Reply: " << response;
923 stream <<
"Reply: " << response.substr(0, maxSize);
938 using namespace boost::beast::http;
940 response<string_body> msg;
944 msg.result(boost::beast::http::status::ok);
945 msg.body() =
"<!DOCTYPE html><html><head><title>" +
systemName() +
946 " Test page for rippled</title></head><body><h1>" +
systemName() +
947 " Test</h1><p>This page shows rippled http(s) "
948 "connectivity is working.</p></body></html>";
952 msg.result(boost::beast::http::status::internal_server_error);
953 msg.body() =
"<HTML><BODY>Server cannot accept clients: " + reason +
956 msg.version(request.version());
958 msg.insert(
"Content-Type",
"text/html");
959 msg.insert(
"Connection",
"close");
960 msg.prepare_payload();
961 handoff.
response = std::make_shared<SimpleWriter>(msg);
970 for (
auto& p :
ports)
974 if (p.ssl_key.empty() && p.ssl_cert.empty() && p.ssl_chain.empty())
978 p.ssl_key, p.ssl_cert, p.ssl_chain, p.ssl_ciphers);
982 p.context = std::make_shared<boost::asio::ssl::context>(
983 boost::asio::ssl::context::sslv23);
996 log <<
"Missing 'ip' in [" << p.
name <<
"]";
997 Throw<std::exception>();
1003 log <<
"Missing 'port' in [" << p.
name <<
"]";
1004 Throw<std::exception>();
1006 else if (*parsed.
port == 0)
1008 log <<
"Port " << *parsed.
port <<
"in [" << p.
name <<
"] is invalid";
1009 Throw<std::exception>();
1019 log <<
"Missing 'protocol' in [" << p.
name <<
"]";
1020 Throw<std::exception>();
1044 if (!config.
exists(
"server"))
1046 log <<
"Required section [server] is missing";
1047 Throw<std::exception>();
1055 for (
auto const& name : names)
1057 if (!config.
exists(name))
1059 log <<
"Missing section: [" << name <<
"]";
1060 Throw<std::exception>();
1070 auto it = result.
begin();
1072 while (it != result.
end())
1074 auto& p = it->protocol;
1078 if (p.erase(
"peer") && p.empty())
1079 it = result.
erase(it);
1088 return p.protocol.count(
"peer") != 0;
1093 log <<
"Error: More than one peer protocol configured in [server]";
1094 Throw<std::exception>();
1098 log <<
"Warning: No peer protocol configured";
1110 if (iter->protocol.count(
"http") > 0 ||
1111 iter->protocol.count(
"https") > 0)
1119 (iter->ip.is_v6() ?
"::1" :
"127.0.0.1")
1120 : iter->ip.to_string();
1134 return port.protocol.count(
"peer") != 0;
1145 ServerHandler::Setup
1161 boost::asio::io_service& io_service,
1167 return std::make_unique<ServerHandlerImp>(
1168 app, parent, io_service, jobQueue, networkOPs, resourceManager, cm);
virtual Consumer newInboundEndpoint(beast::IP::Endpoint const &address)=0
Create a new endpoint keyed by inbound IP address or the forwarded IP if proxied.
Provides server functionality for clients.
std::uint16_t ws_queue_limit
std::vector< beast::IP::Address > admin_ip
std::map< std::reference_wrapper< Port const >, int > count_
std::unique_ptr< Server > make_Server(Handler &handler, boost::asio::io_service &io_service, beast::Journal journal)
Create the HTTP server using the specified handler.
bool warn()
Returns true if the consumer should be warned.
virtual Handoff onHandoff(std::unique_ptr< stream_type > &&bundle, http_request_type &&request, boost::asio::ip::tcp::endpoint remote_address)=0
Conditionally accept an incoming HTTP request.
static Json::Output makeOutput(Session &session)
std::shared_ptr< Coro > postCoro(JobType t, std::string const &name, F &&f)
Creates a coroutine and adds a job to the queue which will run it.
void stopped()
Called by derived classes to indicate that the stoppable has stopped.
virtual std::shared_ptr< WSSession > websocketUpgrade()=0
Convert the connection to WebSocket.
Stream trace() const
Severity stream access functions.
void stream(Json::Value const &jv, Write const &write)
Stream compact JSON to the specified function.
unsigned int getAPIVersionNumber(Json::Value const &jv)
Retrieve the api version number from the json value.
@ arrayValue
array value (ordered list)
static Json::Value make_json_error(Json::Int code, Json::Value &&message)
Decorator for streaming out compact json.
std::shared_ptr< boost::asio::ssl::context > make_SSLContext(std::string const &cipherList)
Create a self-signed SSL context that allows anonymous Diffie Hellman.
Resource::Consumer requestInboundEndpoint(Resource::Manager &manager, beast::IP::Endpoint const &remoteAddress, Role const &role, boost::string_view const &user, boost::string_view const &forwardedFor)
Provides the beast::insight::Collector service.
boost::asio::ip::address ip
constexpr Json::Int method_not_found
boost::optional< boost::asio::ip::address > ip
constexpr Json::Int server_overloaded
const Charge feeReferenceRPC
constexpr unsigned int APIVersionIfUnspecified
void HTTPReply(int nStatus, std::string const &content, Json::Output const &output, beast::Journal j)
bool isNull() const
isNull() tests to see if this field is null.
beast::insight::Counter rpc_requests_
std::string to_string(ListDisposition disposition)
void parse_Port(ParsedPort &port, Section const §ion, std::ostream &log)
Unserialize a JSON document into a Value.
Persistent state information for a connection session.
void write(std::string const &s)
Send a copy of data asynchronously.
constexpr Json::Int forbidden
boost::asio::ip::address ip
void onRequest(Session &session)
Handoff statusResponse(http_request_type const &request) const
std::set< std::string, boost::beast::iless > protocol
static bool isStatusRequest(http_request_type const &request)
virtual NetworkOPs & getOPs()=0
void onClose(Session &session, boost::system::error_code const &)
NetworkOPs & m_networkOPs
std::vector< std::string > const & values() const
Returns all the values in the section.
ServerHandlerImp(Application &app, Stoppable &parent, boost::asio::io_service &io_service, JobQueue &jobQueue, NetworkOPs &networkOPs, Resource::Manager &resourceManager, CollectorManager &cm)
std::shared_ptr< boost::asio::ssl::context > make_SSLContextAuthed(std::string const &keyFile, std::string const &certFile, std::string const &chainFile, std::string const &cipherList)
Create an authenticated SSL context using the specified files.
static IP::Endpoint from_asio(boost::asio::ip::address const &address)
beast::insight::Event rpc_time_
ServerHandler::Setup setup_ServerHandler(Config const &config, std::ostream &&log)
virtual beast::insight::Group::ptr const & group(std::string const &name)=0
bool is_keep_alive(boost::beast::http::message< isRequest, Body, Fields > const &m)
Status doCommand(RPC::JsonContext &context, Json::Value &result)
Execute an RPC command and store the results in a Json::Value.
Overlay::Setup setup_Overlay(BasicConfig const &config)
Value & append(const Value &value)
Append value to array at the end.
Provides an interface for starting and stopping.
static Handoff statusRequestResponse(http_request_type const &request, boost::beast::http::status status)
virtual bool serverOkay(std::string &reason)=0
void onStop() override
Override called when the stop notification is issued.
void processRequest(Port const &port, std::string const &request, beast::IP::Endpoint const &remoteIPAddress, Output &&, std::shared_ptr< JobQueue::Coro > coro, boost::string_view forwardedFor, boost::string_view user)
std::shared_ptr< InfoSub > pointer
@ objectValue
object value (collection of name/value pairs).
static bool authorized(Port const &port, std::map< std::string, std::string > const &h)
virtual LedgerMaster & getLedgerMaster()=0
Json::Value processSession(std::shared_ptr< WSSession > const &session, std::shared_ptr< JobQueue::Coro > const &coro, Json::Value const &jv)
static constexpr int maxRequestSize
bool onAccept(Session &session, boost::asio::ip::tcp::endpoint endpoint)
boost::string_view forwardedFor(http_request_type const &request)
std::string base64_decode(std::string const &data)
UInt size() const
Number of values in array or object.
std::vector< beast::IP::Address > secure_gateway_ip
virtual http_request_type & request()=0
Returns the current HTTP request.
beast::insight::Event rpc_size_
boost::optional< std::vector< beast::IP::Address > > secure_gateway_ip
Endpoint from_asio(boost::asio::ip::address const &address)
Convert to Endpoint.
bool isMember(const char *key) const
Return true if the object has a member named key.
A generic endpoint for log messages.
Role requestRole(Role const &required, Port const &port, Json::Value const ¶ms, beast::IP::Endpoint const &remoteIp, boost::string_view const &user)
Return the allowed privilege role.
Configuration information for a Server listening port.
virtual std::shared_ptr< Session > detach()=0
Detach the session.
Json::Value rpcError(int iError, Json::Value jvResult)
constexpr unsigned int APIInvalidVersion
API version numbers used in later API versions.
std::unique_ptr< Server > m_server
const Charge feeInvalidRPC
Resource::Manager & m_resourceManager
static Port to_Port(ParsedPort const &parsed, std::ostream &log)
boost::beast::websocket::permessage_deflate pmd_options
constexpr Json::Int wrong_version
A pool of threads to perform work.
std::string admin_password
bool isUnlimited(Role const &role)
ADMIN and IDENTIFIED roles shall have unlimited resources.
Role roleRequired(unsigned int version, std::string const &method)
Tracks load and resource consumption.
std::string const & getFullVersionString()
Full server version string.
std::string admin_password
void onWSMessage(std::shared_ptr< WSSession > session, std::vector< boost::asio::const_buffer > const &buffers)
Use hash_* containers for keys that do not need a cryptographically secure hashing algorithm.
boost::optional< std::uint16_t > port
static std::string buffers_to_string(ConstBufferSequence const &bs)
virtual beast::Journal journal(std::string const &name)=0
Value removeMember(const char *key)
Remove and return the named member.
virtual Consumer newUnlimitedEndpoint(beast::IP::Endpoint const &address)=0
Create a new unlimited endpoint keyed by forwarded IP.
boost::beast::websocket::permessage_deflate pmd_options
bool disconnect()
Returns true if the consumer should be disconnected.
Setup const & setup() const
bool parse(std::string const &document, Value &root)
Read a Value from a JSON document.
An endpoint that consumes resources.
std::uint16_t ws_queue_limit
static void setup_Client(ServerHandler::Setup &setup)
std::string getFormatedErrorMessages() const
Returns a user friendly string that list errors in the parsed document.
virtual Overlay & overlay()=0
std::vector< Port > ports
virtual Port const & port()=0
Returns the Port settings for this connection.
virtual void close(bool graceful)=0
Close the session.
Used to indicate the result of a server connection handoff.
static std::string const & systemName()
A version-independent IP address and port combination.
std::shared_ptr< Writer > response
boost::optional< std::vector< beast::IP::Address > > admin_ip
static std::map< std::string, std::string > build_map(boost::beast::http::fields const &h)
std::set< std::string, boost::beast::iless > protocol
Disposition charge(Charge const &fee)
Apply a load charge to the consumer.
bool is_unspecified(Address const &addr)
Returns true if the address is unspecified.
boost::beast::http::request< boost::beast::http::dynamic_body > http_request_type
std::string admin_password
bool isObjectOrNull() const
Json::Value make_error(error_code_i code)
Returns a new json object that reflects the error code.
std::unique_ptr< ServerHandler > make_ServerHandler(Application &app, Stoppable &parent, boost::asio::io_service &io_service, JobQueue &jobQueue, NetworkOPs &networkOPs, Resource::Manager &resourceManager, CollectorManager &cm)
Handoff onHandoff(Session &session, std::unique_ptr< stream_type > &&bundle, http_request_type &&request, boost::asio::ip::tcp::endpoint const &remote_address)
bool exists(std::string const &name) const
Returns true if a section with the given name exists.
void notify(std::chrono::duration< Rep, Period > const &value) const
Push an event notification.
static std::vector< Port > parse_Ports(Config const &config, std::ostream &log)
Section & section(std::string const &name)
Returns the section with the given name.
std::string asString() const
Returns the unquoted string value.