source: code/trunk/server.go@ 402

Last change on this file since 402 was 398, checked in by contact, 5 years ago

Implement rate limiting for upstream messages

Allow up to 10 outgoing messages in a burst, then throttle to 1 message
each 2 seconds.

Closes: https://todo.sr.ht/~emersion/soju/87

File size: 3.8 KB
Line 
1package soju
2
3import (
4 "fmt"
5 "log"
6 "net"
7 "net/http"
8 "sync"
9 "sync/atomic"
10 "time"
11
12 "gopkg.in/irc.v3"
13 "nhooyr.io/websocket"
14
15 "git.sr.ht/~emersion/soju/config"
16)
17
18// TODO: make configurable
19var retryConnectDelay = time.Minute
20var connectTimeout = 15 * time.Second
21var writeTimeout = 10 * time.Second
22var upstreamMessageDelay = 2 * time.Second
23var upstreamMessageBurst = 10
24
25type Logger interface {
26 Print(v ...interface{})
27 Printf(format string, v ...interface{})
28}
29
30type prefixLogger struct {
31 logger Logger
32 prefix string
33}
34
35var _ Logger = (*prefixLogger)(nil)
36
37func (l *prefixLogger) Print(v ...interface{}) {
38 v = append([]interface{}{l.prefix}, v...)
39 l.logger.Print(v...)
40}
41
42func (l *prefixLogger) Printf(format string, v ...interface{}) {
43 v = append([]interface{}{l.prefix}, v...)
44 l.logger.Printf("%v"+format, v...)
45}
46
47type Server struct {
48 Hostname string
49 Logger Logger
50 RingCap int
51 HistoryLimit int
52 LogPath string
53 Debug bool
54 HTTPOrigins []string
55 AcceptProxyIPs config.IPSet
56 Identd *Identd // can be nil
57
58 db *DB
59
60 lock sync.Mutex
61 users map[string]*user
62}
63
64func NewServer(db *DB) *Server {
65 return &Server{
66 Logger: log.New(log.Writer(), "", log.LstdFlags),
67 RingCap: 4096,
68 HistoryLimit: 1000,
69 users: make(map[string]*user),
70 db: db,
71 }
72}
73
74func (s *Server) prefix() *irc.Prefix {
75 return &irc.Prefix{Name: s.Hostname}
76}
77
78func (s *Server) Run() error {
79 users, err := s.db.ListUsers()
80 if err != nil {
81 return err
82 }
83
84 s.lock.Lock()
85 for i := range users {
86 s.addUserLocked(&users[i])
87 }
88 s.lock.Unlock()
89
90 select {}
91}
92
93func (s *Server) createUser(user *User) (*user, error) {
94 s.lock.Lock()
95 defer s.lock.Unlock()
96
97 if _, ok := s.users[user.Username]; ok {
98 return nil, fmt.Errorf("user %q already exists", user.Username)
99 }
100
101 err := s.db.StoreUser(user)
102 if err != nil {
103 return nil, fmt.Errorf("could not create user in db: %v", err)
104 }
105
106 return s.addUserLocked(user), nil
107}
108
109func (s *Server) getUser(name string) *user {
110 s.lock.Lock()
111 u := s.users[name]
112 s.lock.Unlock()
113 return u
114}
115
116func (s *Server) addUserLocked(user *User) *user {
117 s.Logger.Printf("starting bouncer for user %q", user.Username)
118 u := newUser(s, user)
119 s.users[u.Username] = u
120
121 go func() {
122 u.run()
123
124 s.lock.Lock()
125 delete(s.users, u.Username)
126 s.lock.Unlock()
127 }()
128
129 return u
130}
131
132var lastDownstreamID uint64 = 0
133
134func (s *Server) handle(ic ircConn) {
135 id := atomic.AddUint64(&lastDownstreamID, 1)
136 dc := newDownstreamConn(s, ic, id)
137 if err := dc.runUntilRegistered(); err != nil {
138 dc.logger.Print(err)
139 } else {
140 dc.user.events <- eventDownstreamConnected{dc}
141 if err := dc.readMessages(dc.user.events); err != nil {
142 dc.logger.Print(err)
143 }
144 dc.user.events <- eventDownstreamDisconnected{dc}
145 }
146 dc.Close()
147}
148
149func (s *Server) Serve(ln net.Listener) error {
150 for {
151 conn, err := ln.Accept()
152 if err != nil {
153 return fmt.Errorf("failed to accept connection: %v", err)
154 }
155
156 go s.handle(newNetIRCConn(conn))
157 }
158}
159
160func (s *Server) ServeHTTP(w http.ResponseWriter, req *http.Request) {
161 conn, err := websocket.Accept(w, req, &websocket.AcceptOptions{
162 OriginPatterns: s.HTTPOrigins,
163 Subprotocols: []string{"irc"},
164 })
165 if err != nil {
166 s.Logger.Printf("failed to serve HTTP connection: %v", err)
167 return
168 }
169
170 isProxy := false
171 if host, _, err := net.SplitHostPort(req.RemoteAddr); err == nil {
172 if ip := net.ParseIP(host); ip != nil {
173 isProxy = s.AcceptProxyIPs.Contains(ip)
174 }
175 }
176
177 // Only trust X-Forwarded-* header fields if this is a trusted proxy IP
178 // to prevent users from spoofing the remote address
179 remoteAddr := req.RemoteAddr
180 forwardedHost := req.Header.Get("X-Forwarded-For")
181 forwardedPort := req.Header.Get("X-Forwarded-Port")
182 if isProxy && forwardedHost != "" && forwardedPort != "" {
183 remoteAddr = net.JoinHostPort(forwardedHost, forwardedPort)
184 }
185
186 s.handle(newWebsocketIRCConn(conn, remoteAddr))
187}
Note: See TracBrowser for help on using the repository browser.