20 #include <ripple/app/main/Application.h>
21 #include <ripple/app/misc/NetworkOPs.h>
22 #include <ripple/basics/Log.h>
23 #include <ripple/basics/base64.h>
24 #include <ripple/basics/contract.h>
25 #include <ripple/basics/make_SSLContext.h>
26 #include <ripple/beast/net/IPAddressConversion.h>
27 #include <ripple/beast/rfc2616.h>
28 #include <ripple/core/JobQueue.h>
29 #include <ripple/json/json_reader.h>
30 #include <ripple/json/to_string.h>
31 #include <ripple/net/RPCErr.h>
32 #include <ripple/overlay/Overlay.h>
33 #include <ripple/resource/Fees.h>
34 #include <ripple/resource/ResourceManager.h>
35 #include <ripple/rpc/RPCHandler.h>
36 #include <ripple/rpc/Role.h>
37 #include <ripple/rpc/ServerHandler.h>
38 #include <ripple/rpc/impl/RPCHelpers.h>
39 #include <ripple/rpc/impl/ServerHandlerImp.h>
40 #include <ripple/rpc/impl/Tuning.h>
41 #include <ripple/rpc/json_body.h>
42 #include <ripple/server/Server.h>
43 #include <ripple/server/SimpleWriter.h>
44 #include <ripple/server/impl/JSONRPCUtil.h>
45 #include <boost/algorithm/string.hpp>
46 #include <boost/beast/http/fields.hpp>
47 #include <boost/beast/http/string_body.hpp>
48 #include <boost/regex.hpp>
49 #include <boost/type_traits.hpp>
58 return request.version() >= 11 && request.target() ==
"/" &&
59 request.body().size() == 0 &&
60 request.method() == boost::beast::http::verb::get;
66 boost::beast::http::status status)
68 using namespace boost::beast::http;
70 response<string_body> msg;
71 msg.version(request.version());
74 msg.insert(
"Content-Type",
"text/html");
75 msg.insert(
"Connection",
"close");
76 msg.body() =
"Invalid protocol.";
77 msg.prepare_payload();
78 handoff.
response = std::make_shared<SimpleWriter>(msg);
89 auto const it = h.
find(
"authorization");
90 if ((it == h.
end()) || (it->second.substr(0, 6) !=
"Basic "))
93 boost::trim(strUserPass64);
95 std::string::size_type nColon = strUserPass.
find(
":");
96 if (nColon == std::string::npos)
100 return strUser == port.
user && strPassword == port.
password;
106 boost::asio::io_service& io_service,
113 , m_resourceManager(resourceManager)
114 , m_journal(app_.journal(
"Server"))
115 , m_networkOPs(networkOPs)
116 , m_server(
make_Server(*this, io_service, app_.journal(
"Server")))
117 , m_jobQueue(jobQueue)
119 auto const& group(cm.
group(
"rpc"));
150 boost::asio::ip::tcp::endpoint endpoint)
159 << session.
port().
name <<
" is full; dropping " << endpoint;
171 boost::asio::ip::tcp::endpoint
const& remote_address)
173 using namespace boost::beast;
176 p.
count(
"ws") > 0 || p.count(
"ws2") > 0 || p.count(
"wss") > 0 ||
177 p.count(
"wss2") > 0};
179 if (websocket::is_upgrade(request))
192 <<
"Exception upgrading websocket: " << e.
what() <<
"\n";
194 request, http::status::internal_server_error);
198 auto const beast_remote_address =
202 beast_remote_address,
207 beast_remote_address,
210 is->forwarded_for());
211 ws->appDefined = std::move(is);
215 handoff.
moved =
true;
219 if (bundle && p.count(
"peer") > 0)
221 std::move(bundle), std::move(request), remote_address);
233 return [&](boost::beast::string_view
const& b) {
234 session.
write(b.data(), b.size());
242 for (
auto const& e : h)
244 auto key(e.name_string().to_string());
246 return std::tolower(static_cast<unsigned char>(kc));
248 c[key] = e.value().to_string();
253 template <
class ConstBufferSequence>
257 using boost::asio::buffer_cast;
258 using boost::asio::buffer_size;
261 for (
auto const& b : bs)
262 s.
append(buffer_cast<char const*>(b), buffer_size(b));
293 if (postResult ==
nullptr)
298 "Service Unavailable",
301 detachedSession->close(
true);
312 auto const size = boost::asio::buffer_size(buffers);
317 jvResult[jss::type] = jss::error;
318 jvResult[jss::error] =
"jsonInvalid";
320 boost::beast::multi_buffer sb;
321 Json::stream(jvResult, [&sb](
auto const p,
auto const n) {
322 sb.commit(boost::asio::buffer_copy(
323 sb.prepare(n), boost::asio::buffer(p, n)));
325 JLOG(
m_journal.
trace()) <<
"Websocket sending '" << jvResult <<
"'";
337 [
this, session, jv = std::move(jv)](
341 auto const n = s.length();
342 boost::beast::multi_buffer sb(n);
343 sb.commit(boost::asio::buffer_copy(
344 sb.prepare(n), boost::asio::buffer(s.c_str(), n)));
349 if (postResult ==
nullptr)
352 session->close({boost::beast::websocket::going_away,
"Shutting Down"});
377 auto is = std::static_pointer_cast<WSInfoSub>(session->appDefined);
378 if (is->getConsumer().disconnect())
381 {boost::beast::websocket::policy_error,
"threshold exceeded"});
400 jr[jss::type] = jss::response;
401 jr[jss::status] = jss::error;
403 ? jss::invalid_API_version
404 : jss::missingCommand;
405 jr[jss::request] = jv;
407 jr[jss::id] = jv[jss::id];
409 jr[jss::jsonrpc] = jv[jss::jsonrpc];
411 jr[jss::ripplerpc] = jv[jss::ripplerpc];
413 jr[jss::api_version] = jv[jss::api_version];
448 {is->user(), is->forwarded_for()}};
457 <<
"Exception while processing WS: " << ex.
what() <<
"\n"
461 is->getConsumer().charge(loadType);
462 if (is->getConsumer().warn())
463 jr[jss::warning] = jss::load;
470 if (jr[jss::result].isMember(jss::error))
472 jr = jr[jss::result];
473 jr[jss::status] = jss::error;
479 if (rq.isMember(jss::passphrase.c_str()))
480 rq[jss::passphrase.c_str()] =
"<masked>";
481 if (rq.isMember(jss::secret.c_str()))
482 rq[jss::secret.c_str()] =
"<masked>";
483 if (rq.isMember(jss::seed.c_str()))
484 rq[jss::seed.c_str()] =
"<masked>";
485 if (rq.isMember(jss::seed_hex.c_str()))
486 rq[jss::seed_hex.c_str()] =
"<masked>";
489 jr[jss::request] = rq;
493 if (jr[jss::result].isMember(
"forwarded") &&
494 jr[jss::result][
"forwarded"])
495 jr = jr[jss::result];
496 jr[jss::status] = jss::success;
500 jr[jss::id] = jv[jss::id];
502 jr[jss::jsonrpc] = jv[jss::jsonrpc];
504 jr[jss::ripplerpc] = jv[jss::ripplerpc];
506 jr[jss::api_version] = jv[jss::api_version];
508 jr[jss::type] = jss::response;
521 session->remoteAddress().at_port(0),
526 auto const iter = session->request().find(
"X-User");
527 if (iter != session->request().end())
528 return iter->value();
529 return boost::beast::string_view{};
535 session->close(
true);
543 sub[
"message"] = std::move(message);
562 boost::string_view user)
570 !reader.
parse(request, jsonOrig) || !jsonOrig ||
584 if (jsonOrig.
isMember(jss::method) && jsonOrig[jss::method] ==
"batch")
587 if (!jsonOrig.
isMember(jss::params) || !jsonOrig[jss::params].
isArray())
589 HTTPReply(400,
"Malformed batch request", output, rpcJ);
592 size = jsonOrig[jss::params].
size();
597 for (
unsigned i = 0; i < size; ++i)
600 batch ? jsonOrig[jss::params][i] : jsonOrig;
605 r[jss::request] = jsonRPC;
614 jsonRPC[jss::params].
size() > 0 &&
615 jsonRPC[jss::params][0u].
isObject())
631 HTTPReply(400, jss::invalid_API_version.c_str(), output, rpcJ);
635 r[jss::request] = jsonRPC;
650 jsonRPC[jss::params].
size() > 0 &&
679 HTTPReply(503,
"Server is overloaded", output, rpcJ);
695 HTTPReply(403,
"Forbidden", output, rpcJ);
704 if (!jsonRPC.
isMember(jss::method) || jsonRPC[jss::method].
isNull())
709 HTTPReply(400,
"Null method", output, rpcJ);
724 HTTPReply(400,
"method is not string", output, rpcJ);
735 if (strMethod.
empty())
740 HTTPReply(400,
"method is empty", output, rpcJ);
759 params = jsonRPC[jss::params];
766 HTTPReply(400,
"params unparseable", output, rpcJ);
771 params = std::move(params[0u]);
775 HTTPReply(400,
"params unparseable", output, rpcJ);
786 if (params.
isMember(jss::ripplerpc))
788 if (!params[jss::ripplerpc].isString())
793 HTTPReply(400,
"ripplerpc is not a string", output, rpcJ);
803 ripplerpc = params[jss::ripplerpc].
asString();
819 params[jss::command] = strMethod;
821 <<
"doRpcCommand:" << strMethod <<
":" << params;
842 result[jss::warning] = jss::load;
845 if (ripplerpc >=
"2.0")
849 result[jss::status] = jss::error;
850 result[
"code"] = result[jss::error_code];
851 result[
"message"] = result[jss::error_message];
854 <<
": " << result[jss::error_message];
855 r[jss::error] = std::move(result);
859 result[jss::status] = jss::success;
860 r[jss::result] = std::move(result);
873 if (rq.isMember(jss::passphrase.c_str()))
874 rq[jss::passphrase.c_str()] =
"<masked>";
875 if (rq.isMember(jss::secret.c_str()))
876 rq[jss::secret.c_str()] =
"<masked>";
877 if (rq.isMember(jss::seed.c_str()))
878 rq[jss::seed.c_str()] =
"<masked>";
879 if (rq.isMember(jss::seed_hex.c_str()))
880 rq[jss::seed_hex.c_str()] =
"<masked>";
883 result[jss::status] = jss::error;
884 result[jss::request] = rq;
887 <<
": " << result[jss::error_message];
891 result[jss::status] = jss::success;
893 r[jss::result] = std::move(result);
896 if (params.isMember(jss::jsonrpc))
897 r[jss::jsonrpc] = params[jss::jsonrpc];
898 if (params.isMember(jss::ripplerpc))
899 r[jss::ripplerpc] = params[jss::ripplerpc];
900 if (params.isMember(jss::id))
901 r[jss::id] = params[jss::id];
903 reply.
append(std::move(r));
905 reply = std::move(r);
909 rpc_time_.
notify(std::chrono::duration_cast<std::chrono::milliseconds>(
918 static const int maxSize = 10000;
919 if (response.size() <= maxSize)
920 stream <<
"Reply: " << response;
922 stream <<
"Reply: " << response.substr(0, maxSize);
937 using namespace boost::beast::http;
939 response<string_body> msg;
943 msg.result(boost::beast::http::status::ok);
944 msg.body() =
"<!DOCTYPE html><html><head><title>" +
systemName() +
945 " Test page for rippled</title></head><body><h1>" +
systemName() +
946 " Test</h1><p>This page shows rippled http(s) "
947 "connectivity is working.</p></body></html>";
951 msg.result(boost::beast::http::status::internal_server_error);
952 msg.body() =
"<HTML><BODY>Server cannot accept clients: " + reason +
955 msg.version(request.version());
957 msg.insert(
"Content-Type",
"text/html");
958 msg.insert(
"Connection",
"close");
959 msg.prepare_payload();
960 handoff.
response = std::make_shared<SimpleWriter>(msg);
969 for (
auto& p :
ports)
973 if (p.ssl_key.empty() && p.ssl_cert.empty() && p.ssl_chain.empty())
977 p.ssl_key, p.ssl_cert, p.ssl_chain, p.ssl_ciphers);
981 p.context = std::make_shared<boost::asio::ssl::context>(
982 boost::asio::ssl::context::sslv23);
995 log <<
"Missing 'ip' in [" << p.
name <<
"]";
996 Throw<std::exception>();
1002 log <<
"Missing 'port' in [" << p.
name <<
"]";
1003 Throw<std::exception>();
1005 else if (*parsed.
port == 0)
1007 log <<
"Port " << *parsed.
port <<
"in [" << p.
name <<
"] is invalid";
1008 Throw<std::exception>();
1018 log <<
"Missing 'protocol' in [" << p.
name <<
"]";
1019 Throw<std::exception>();
1043 if (!config.
exists(
"server"))
1045 log <<
"Required section [server] is missing";
1046 Throw<std::exception>();
1054 for (
auto const& name : names)
1056 if (!config.
exists(name))
1058 log <<
"Missing section: [" << name <<
"]";
1059 Throw<std::exception>();
1069 auto it = result.
begin();
1071 while (it != result.
end())
1073 auto& p = it->protocol;
1077 if (p.erase(
"peer") && p.empty())
1078 it = result.
erase(it);
1087 return p.protocol.count(
"peer") != 0;
1092 log <<
"Error: More than one peer protocol configured in [server]";
1093 Throw<std::exception>();
1097 log <<
"Warning: No peer protocol configured";
1109 if (iter->protocol.count(
"http") > 0 ||
1110 iter->protocol.count(
"https") > 0)
1118 (iter->ip.is_v6() ?
"::1" :
"127.0.0.1")
1119 : iter->ip.to_string();
1133 return port.protocol.count(
"peer") != 0;
1144 ServerHandler::Setup
1160 boost::asio::io_service& io_service,
1166 return std::make_unique<ServerHandlerImp>(
1167 app, parent, io_service, jobQueue, networkOPs, resourceManager, cm);
virtual Consumer newInboundEndpoint(beast::IP::Endpoint const &address)=0
Create a new endpoint keyed by inbound IP address or the forwarded IP if proxied.
Provides server functionality for clients.
std::uint16_t ws_queue_limit
std::vector< beast::IP::Address > admin_ip
std::map< std::reference_wrapper< Port const >, int > count_
std::unique_ptr< Server > make_Server(Handler &handler, boost::asio::io_service &io_service, beast::Journal journal)
Create the HTTP server using the specified handler.
std::optional< std::vector< beast::IP::Address > > admin_ip
bool warn()
Returns true if the consumer should be warned.
virtual Handoff onHandoff(std::unique_ptr< stream_type > &&bundle, http_request_type &&request, boost::asio::ip::tcp::endpoint remote_address)=0
Conditionally accept an incoming HTTP request.
static Json::Output makeOutput(Session &session)
std::shared_ptr< Coro > postCoro(JobType t, std::string const &name, F &&f)
Creates a coroutine and adds a job to the queue which will run it.
void stopped()
Called by derived classes to indicate that the stoppable has stopped.
virtual std::shared_ptr< WSSession > websocketUpgrade()=0
Convert the connection to WebSocket.
Stream trace() const
Severity stream access functions.
void stream(Json::Value const &jv, Write const &write)
Stream compact JSON to the specified function.
unsigned int getAPIVersionNumber(Json::Value const &jv)
Retrieve the api version number from the json value.
@ arrayValue
array value (ordered list)
static Json::Value make_json_error(Json::Int code, Json::Value &&message)
Decorator for streaming out compact json.
std::shared_ptr< boost::asio::ssl::context > make_SSLContext(std::string const &cipherList)
Create a self-signed SSL context that allows anonymous Diffie Hellman.
Resource::Consumer requestInboundEndpoint(Resource::Manager &manager, beast::IP::Endpoint const &remoteAddress, Role const &role, boost::string_view const &user, boost::string_view const &forwardedFor)
Provides the beast::insight::Collector service.
boost::asio::ip::address ip
constexpr Json::Int method_not_found
constexpr Json::Int server_overloaded
const Charge feeReferenceRPC
constexpr unsigned int APIVersionIfUnspecified
void HTTPReply(int nStatus, std::string const &content, Json::Output const &output, beast::Journal j)
bool isNull() const
isNull() tests to see if this field is null.
beast::insight::Counter rpc_requests_
void parse_Port(ParsedPort &port, Section const §ion, std::ostream &log)
Unserialize a JSON document into a Value.
Persistent state information for a connection session.
void write(std::string const &s)
Send a copy of data asynchronously.
constexpr Json::Int forbidden
boost::asio::ip::address ip
void onRequest(Session &session)
Handoff statusResponse(http_request_type const &request) const
std::set< std::string, boost::beast::iless > protocol
static bool isStatusRequest(http_request_type const &request)
virtual NetworkOPs & getOPs()=0
void onClose(Session &session, boost::system::error_code const &)
NetworkOPs & m_networkOPs
std::vector< std::string > const & values() const
Returns all the values in the section.
ServerHandlerImp(Application &app, Stoppable &parent, boost::asio::io_service &io_service, JobQueue &jobQueue, NetworkOPs &networkOPs, Resource::Manager &resourceManager, CollectorManager &cm)
std::shared_ptr< boost::asio::ssl::context > make_SSLContextAuthed(std::string const &keyFile, std::string const &certFile, std::string const &chainFile, std::string const &cipherList)
Create an authenticated SSL context using the specified files.
static IP::Endpoint from_asio(boost::asio::ip::address const &address)
beast::insight::Event rpc_time_
ServerHandler::Setup setup_ServerHandler(Config const &config, std::ostream &&log)
virtual beast::insight::Group::ptr const & group(std::string const &name)=0
bool is_keep_alive(boost::beast::http::message< isRequest, Body, Fields > const &m)
Status doCommand(RPC::JsonContext &context, Json::Value &result)
Execute an RPC command and store the results in a Json::Value.
Overlay::Setup setup_Overlay(BasicConfig const &config)
Value & append(const Value &value)
Append value to array at the end.
Provides an interface for starting and stopping.
static Handoff statusRequestResponse(http_request_type const &request, boost::beast::http::status status)
virtual bool serverOkay(std::string &reason)=0
void onStop() override
Override called when the stop notification is issued.
void processRequest(Port const &port, std::string const &request, beast::IP::Endpoint const &remoteIPAddress, Output &&, std::shared_ptr< JobQueue::Coro > coro, boost::string_view forwardedFor, boost::string_view user)
std::shared_ptr< InfoSub > pointer
@ objectValue
object value (collection of name/value pairs).
static bool authorized(Port const &port, std::map< std::string, std::string > const &h)
virtual LedgerMaster & getLedgerMaster()=0
Json::Value processSession(std::shared_ptr< WSSession > const &session, std::shared_ptr< JobQueue::Coro > const &coro, Json::Value const &jv)
static constexpr int maxRequestSize
std::optional< std::vector< beast::IP::Address > > secure_gateway_ip
bool onAccept(Session &session, boost::asio::ip::tcp::endpoint endpoint)
boost::string_view forwardedFor(http_request_type const &request)
std::string base64_decode(std::string const &data)
UInt size() const
Number of values in array or object.
std::vector< beast::IP::Address > secure_gateway_ip
virtual http_request_type & request()=0
Returns the current HTTP request.
beast::insight::Event rpc_size_
Endpoint from_asio(boost::asio::ip::address const &address)
Convert to Endpoint.
bool isMember(const char *key) const
Return true if the object has a member named key.
A generic endpoint for log messages.
Role requestRole(Role const &required, Port const &port, Json::Value const ¶ms, beast::IP::Endpoint const &remoteIp, boost::string_view const &user)
Return the allowed privilege role.
Configuration information for a Server listening port.
virtual std::shared_ptr< Session > detach()=0
Detach the session.
Json::Value rpcError(int iError, Json::Value jvResult)
constexpr unsigned int APIInvalidVersion
API version numbers used in later API versions.
std::unique_ptr< Server > m_server
const Charge feeInvalidRPC
Resource::Manager & m_resourceManager
static Port to_Port(ParsedPort const &parsed, std::ostream &log)
boost::beast::websocket::permessage_deflate pmd_options
constexpr Json::Int wrong_version
A pool of threads to perform work.
std::string admin_password
bool isUnlimited(Role const &role)
ADMIN and IDENTIFIED roles shall have unlimited resources.
Role roleRequired(unsigned int version, std::string const &method)
Tracks load and resource consumption.
std::string const & getFullVersionString()
Full server version string.
std::string admin_password
void onWSMessage(std::shared_ptr< WSSession > session, std::vector< boost::asio::const_buffer > const &buffers)
Use hash_* containers for keys that do not need a cryptographically secure hashing algorithm.
static std::string buffers_to_string(ConstBufferSequence const &bs)
virtual beast::Journal journal(std::string const &name)=0
std::optional< boost::asio::ip::address > ip
Value removeMember(const char *key)
Remove and return the named member.
virtual Consumer newUnlimitedEndpoint(beast::IP::Endpoint const &address)=0
Create a new unlimited endpoint keyed by forwarded IP.
boost::beast::websocket::permessage_deflate pmd_options
std::optional< std::uint16_t > port
bool disconnect()
Returns true if the consumer should be disconnected.
Setup const & setup() const
bool parse(std::string const &document, Value &root)
Read a Value from a JSON document.
An endpoint that consumes resources.
std::uint16_t ws_queue_limit
static void setup_Client(ServerHandler::Setup &setup)
std::string getFormatedErrorMessages() const
Returns a user friendly string that list errors in the parsed document.
virtual Overlay & overlay()=0
std::vector< Port > ports
virtual Port const & port()=0
Returns the Port settings for this connection.
virtual void close(bool graceful)=0
Close the session.
Used to indicate the result of a server connection handoff.
static std::string const & systemName()
std::string to_string(Manifest const &m)
Format the specified manifest to a string for debugging purposes.
A version-independent IP address and port combination.
std::shared_ptr< Writer > response
static std::map< std::string, std::string > build_map(boost::beast::http::fields const &h)
std::set< std::string, boost::beast::iless > protocol
Disposition charge(Charge const &fee)
Apply a load charge to the consumer.
bool is_unspecified(Address const &addr)
Returns true if the address is unspecified.
boost::beast::http::request< boost::beast::http::dynamic_body > http_request_type
std::string admin_password
bool isObjectOrNull() const
Json::Value make_error(error_code_i code)
Returns a new json object that reflects the error code.
std::unique_ptr< ServerHandler > make_ServerHandler(Application &app, Stoppable &parent, boost::asio::io_service &io_service, JobQueue &jobQueue, NetworkOPs &networkOPs, Resource::Manager &resourceManager, CollectorManager &cm)
Handoff onHandoff(Session &session, std::unique_ptr< stream_type > &&bundle, http_request_type &&request, boost::asio::ip::tcp::endpoint const &remote_address)
bool exists(std::string const &name) const
Returns true if a section with the given name exists.
void notify(std::chrono::duration< Rep, Period > const &value) const
Push an event notification.
static std::vector< Port > parse_Ports(Config const &config, std::ostream &log)
Section & section(std::string const &name)
Returns the section with the given name.
std::string asString() const
Returns the unquoted string value.