2020-01-01 23:42:45 +03:00
|
|
|
package http
|
|
|
|
|
|
|
|
import (
|
2021-02-26 02:45:45 +01:00
|
|
|
"crypto/rsa"
|
|
|
|
"crypto/x509"
|
|
|
|
"encoding/base64"
|
2020-01-01 23:42:45 +03:00
|
|
|
"encoding/json"
|
2021-03-03 13:33:56 +01:00
|
|
|
"encoding/pem"
|
2024-01-10 01:42:10 +01:00
|
|
|
"errors"
|
2020-01-01 23:42:45 +03:00
|
|
|
"io"
|
|
|
|
"net/http"
|
|
|
|
"strings"
|
2021-02-26 02:45:45 +01:00
|
|
|
"time"
|
2020-01-01 23:42:45 +03:00
|
|
|
|
|
|
|
"github.com/gorilla/mux"
|
|
|
|
|
|
|
|
"github.com/elyby/chrly/model"
|
2024-01-10 01:42:10 +01:00
|
|
|
"github.com/elyby/chrly/mojang"
|
2023-12-22 01:56:02 +01:00
|
|
|
"github.com/elyby/chrly/utils"
|
2020-01-01 23:42:45 +03:00
|
|
|
)
|
|
|
|
|
2021-02-26 02:45:45 +01:00
|
|
|
var timeNow = time.Now
|
|
|
|
|
2020-01-01 23:42:45 +03:00
|
|
|
type SkinsRepository interface {
|
2020-04-20 22:18:27 +03:00
|
|
|
FindSkinByUsername(username string) (*model.Skin, error)
|
|
|
|
FindSkinByUserId(id int) (*model.Skin, error)
|
|
|
|
SaveSkin(skin *model.Skin) error
|
|
|
|
RemoveSkinByUserId(id int) error
|
|
|
|
RemoveSkinByUsername(username string) error
|
2020-01-01 23:42:45 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
type CapesRepository interface {
|
2020-04-20 22:18:27 +03:00
|
|
|
FindCapeByUsername(username string) (*model.Cape, error)
|
2020-01-01 23:42:45 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
type MojangTexturesProvider interface {
|
|
|
|
GetForUsername(username string) (*mojang.SignedTexturesResponse, error)
|
|
|
|
}
|
|
|
|
|
2021-02-26 02:45:45 +01:00
|
|
|
type TexturesSigner interface {
|
|
|
|
SignTextures(textures string) (string, error)
|
|
|
|
GetPublicKey() (*rsa.PublicKey, error)
|
|
|
|
}
|
|
|
|
|
2020-01-01 23:42:45 +03:00
|
|
|
type Skinsystem struct {
|
2020-01-29 01:34:15 +03:00
|
|
|
Emitter
|
|
|
|
SkinsRepo SkinsRepository
|
|
|
|
CapesRepo CapesRepository
|
|
|
|
MojangTexturesProvider MojangTexturesProvider
|
2021-02-26 02:45:45 +01:00
|
|
|
TexturesSigner TexturesSigner
|
2020-04-19 02:31:09 +03:00
|
|
|
TexturesExtraParamName string
|
|
|
|
TexturesExtraParamValue string
|
2020-01-01 23:42:45 +03:00
|
|
|
}
|
|
|
|
|
2021-02-26 02:45:45 +01:00
|
|
|
type profile struct {
|
|
|
|
Id string
|
|
|
|
Username string
|
|
|
|
Textures *mojang.TexturesResponse
|
|
|
|
CapeFile io.Reader
|
|
|
|
MojangTextures string
|
|
|
|
MojangSignature string
|
|
|
|
}
|
|
|
|
|
2020-04-19 02:31:09 +03:00
|
|
|
func (ctx *Skinsystem) Handler() *mux.Router {
|
2020-01-01 23:42:45 +03:00
|
|
|
router := mux.NewRouter().StrictSlash(true)
|
|
|
|
|
2020-04-19 02:31:09 +03:00
|
|
|
router.HandleFunc("/skins/{username}", ctx.skinHandler).Methods(http.MethodGet)
|
|
|
|
router.HandleFunc("/cloaks/{username}", ctx.capeHandler).Methods(http.MethodGet).Name("cloaks")
|
|
|
|
router.HandleFunc("/textures/{username}", ctx.texturesHandler).Methods(http.MethodGet)
|
|
|
|
router.HandleFunc("/textures/signed/{username}", ctx.signedTexturesHandler).Methods(http.MethodGet)
|
2021-02-26 02:45:45 +01:00
|
|
|
router.HandleFunc("/profile/{username}", ctx.profileHandler).Methods(http.MethodGet)
|
2020-01-01 23:42:45 +03:00
|
|
|
// Legacy
|
2020-04-19 02:31:09 +03:00
|
|
|
router.HandleFunc("/skins", ctx.skinGetHandler).Methods(http.MethodGet)
|
|
|
|
router.HandleFunc("/cloaks", ctx.capeGetHandler).Methods(http.MethodGet)
|
2021-02-26 02:45:45 +01:00
|
|
|
// Utils
|
2021-03-03 13:33:56 +01:00
|
|
|
router.HandleFunc("/signature-verification-key.der", ctx.signatureVerificationKeyHandler).Methods(http.MethodGet)
|
|
|
|
router.HandleFunc("/signature-verification-key.pem", ctx.signatureVerificationKeyHandler).Methods(http.MethodGet)
|
2020-01-01 23:42:45 +03:00
|
|
|
|
|
|
|
return router
|
|
|
|
}
|
|
|
|
|
2020-04-19 02:31:09 +03:00
|
|
|
func (ctx *Skinsystem) skinHandler(response http.ResponseWriter, request *http.Request) {
|
2021-02-26 02:45:45 +01:00
|
|
|
profile, err := ctx.getProfile(request, true)
|
|
|
|
if err != nil {
|
|
|
|
panic(err)
|
2020-04-29 21:54:40 +03:00
|
|
|
}
|
|
|
|
|
2021-02-26 02:45:45 +01:00
|
|
|
if profile == nil || profile.Textures == nil || profile.Textures.Skin == nil {
|
2020-01-01 23:42:45 +03:00
|
|
|
response.WriteHeader(http.StatusNotFound)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2021-02-26 02:45:45 +01:00
|
|
|
http.Redirect(response, request, profile.Textures.Skin.Url, 301)
|
2020-01-01 23:42:45 +03:00
|
|
|
}
|
|
|
|
|
2020-04-19 02:31:09 +03:00
|
|
|
func (ctx *Skinsystem) skinGetHandler(response http.ResponseWriter, request *http.Request) {
|
2020-01-01 23:42:45 +03:00
|
|
|
username := request.URL.Query().Get("name")
|
|
|
|
if username == "" {
|
|
|
|
response.WriteHeader(http.StatusBadRequest)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
mux.Vars(request)["username"] = username
|
|
|
|
|
2020-04-19 02:31:09 +03:00
|
|
|
ctx.skinHandler(response, request)
|
2020-01-01 23:42:45 +03:00
|
|
|
}
|
|
|
|
|
2020-04-19 02:31:09 +03:00
|
|
|
func (ctx *Skinsystem) capeHandler(response http.ResponseWriter, request *http.Request) {
|
2021-02-26 02:45:45 +01:00
|
|
|
profile, err := ctx.getProfile(request, true)
|
|
|
|
if err != nil {
|
|
|
|
panic(err)
|
2020-01-01 23:42:45 +03:00
|
|
|
}
|
|
|
|
|
2021-02-26 02:45:45 +01:00
|
|
|
if profile == nil || profile.Textures == nil || (profile.CapeFile == nil && profile.Textures.Cape == nil) {
|
2020-04-29 21:54:40 +03:00
|
|
|
response.WriteHeader(http.StatusNotFound)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2021-02-26 02:45:45 +01:00
|
|
|
if profile.CapeFile == nil {
|
|
|
|
http.Redirect(response, request, profile.Textures.Cape.Url, 301)
|
|
|
|
} else {
|
|
|
|
request.Header.Set("Content-Type", "image/png")
|
|
|
|
_, _ = io.Copy(response, profile.CapeFile)
|
2020-01-01 23:42:45 +03:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-04-19 02:31:09 +03:00
|
|
|
func (ctx *Skinsystem) capeGetHandler(response http.ResponseWriter, request *http.Request) {
|
2020-01-01 23:42:45 +03:00
|
|
|
username := request.URL.Query().Get("name")
|
|
|
|
if username == "" {
|
|
|
|
response.WriteHeader(http.StatusBadRequest)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
mux.Vars(request)["username"] = username
|
|
|
|
|
2020-04-19 02:31:09 +03:00
|
|
|
ctx.capeHandler(response, request)
|
2020-01-01 23:42:45 +03:00
|
|
|
}
|
|
|
|
|
2020-04-19 02:31:09 +03:00
|
|
|
func (ctx *Skinsystem) texturesHandler(response http.ResponseWriter, request *http.Request) {
|
2021-02-26 02:45:45 +01:00
|
|
|
profile, err := ctx.getProfile(request, true)
|
|
|
|
if err != nil {
|
|
|
|
panic(err)
|
|
|
|
}
|
|
|
|
|
|
|
|
if profile == nil || profile.Textures == nil || (profile.Textures.Skin == nil && profile.Textures.Cape == nil) {
|
|
|
|
response.WriteHeader(http.StatusNoContent)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
responseData, _ := json.Marshal(profile.Textures)
|
|
|
|
response.Header().Set("Content-Type", "application/json")
|
|
|
|
_, _ = response.Write(responseData)
|
|
|
|
}
|
|
|
|
|
|
|
|
func (ctx *Skinsystem) signedTexturesHandler(response http.ResponseWriter, request *http.Request) {
|
|
|
|
profile, err := ctx.getProfile(request, request.URL.Query().Get("proxy") != "")
|
|
|
|
if err != nil {
|
|
|
|
panic(err)
|
|
|
|
}
|
|
|
|
|
|
|
|
if profile == nil || profile.MojangTextures == "" {
|
|
|
|
response.WriteHeader(http.StatusNoContent)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
profileResponse := &mojang.SignedTexturesResponse{
|
|
|
|
Id: profile.Id,
|
|
|
|
Name: profile.Username,
|
|
|
|
Props: []*mojang.Property{
|
|
|
|
{
|
|
|
|
Name: "textures",
|
|
|
|
Signature: profile.MojangSignature,
|
|
|
|
Value: profile.MojangTextures,
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Name: ctx.TexturesExtraParamName,
|
|
|
|
Value: ctx.TexturesExtraParamValue,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
responseJson, _ := json.Marshal(profileResponse)
|
|
|
|
response.Header().Set("Content-Type", "application/json")
|
|
|
|
_, _ = response.Write(responseJson)
|
|
|
|
}
|
|
|
|
|
|
|
|
func (ctx *Skinsystem) profileHandler(response http.ResponseWriter, request *http.Request) {
|
|
|
|
profile, err := ctx.getProfile(request, true)
|
|
|
|
if err != nil {
|
|
|
|
panic(err)
|
|
|
|
}
|
|
|
|
|
|
|
|
if profile == nil {
|
|
|
|
response.WriteHeader(http.StatusNoContent)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
texturesPropContent := &mojang.TexturesProp{
|
|
|
|
Timestamp: utils.UnixMillisecond(timeNow()),
|
|
|
|
ProfileID: profile.Id,
|
|
|
|
ProfileName: profile.Username,
|
|
|
|
Textures: profile.Textures,
|
|
|
|
}
|
|
|
|
|
|
|
|
texturesPropValueJson, _ := json.Marshal(texturesPropContent)
|
|
|
|
texturesPropEncodedValue := base64.StdEncoding.EncodeToString(texturesPropValueJson)
|
|
|
|
|
|
|
|
texturesProp := &mojang.Property{
|
|
|
|
Name: "textures",
|
|
|
|
Value: texturesPropEncodedValue,
|
|
|
|
}
|
|
|
|
|
|
|
|
if request.URL.Query().Get("unsigned") == "false" {
|
|
|
|
signature, err := ctx.TexturesSigner.SignTextures(texturesProp.Value)
|
|
|
|
if err != nil {
|
|
|
|
panic(err)
|
|
|
|
}
|
|
|
|
|
|
|
|
texturesProp.Signature = signature
|
|
|
|
}
|
|
|
|
|
|
|
|
profileResponse := &mojang.SignedTexturesResponse{
|
|
|
|
Id: profile.Id,
|
|
|
|
Name: profile.Username,
|
|
|
|
Props: []*mojang.Property{
|
|
|
|
texturesProp,
|
|
|
|
{
|
|
|
|
Name: ctx.TexturesExtraParamName,
|
|
|
|
Value: ctx.TexturesExtraParamValue,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
responseJson, _ := json.Marshal(profileResponse)
|
|
|
|
response.Header().Set("Content-Type", "application/json")
|
|
|
|
_, _ = response.Write(responseJson)
|
|
|
|
}
|
|
|
|
|
2021-02-27 02:37:59 +01:00
|
|
|
func (ctx *Skinsystem) signatureVerificationKeyHandler(response http.ResponseWriter, request *http.Request) {
|
2021-02-26 02:45:45 +01:00
|
|
|
publicKey, err := ctx.TexturesSigner.GetPublicKey()
|
|
|
|
if err != nil {
|
|
|
|
panic(err)
|
|
|
|
}
|
|
|
|
|
|
|
|
asn1Bytes, err := x509.MarshalPKIXPublicKey(publicKey)
|
|
|
|
if err != nil {
|
|
|
|
panic(err)
|
|
|
|
}
|
|
|
|
|
2021-03-03 13:33:56 +01:00
|
|
|
if strings.HasSuffix(request.URL.Path, ".pem") {
|
|
|
|
publicKeyBlock := pem.Block{
|
|
|
|
Type: "PUBLIC KEY",
|
|
|
|
Bytes: asn1Bytes,
|
|
|
|
}
|
|
|
|
|
|
|
|
publicKeyPemBytes := pem.EncodeToMemory(&publicKeyBlock)
|
|
|
|
|
|
|
|
response.Header().Set("Content-Disposition", "attachment; filename=\"yggdrasil_session_pubkey.pem\"")
|
|
|
|
_, _ = response.Write(publicKeyPemBytes)
|
|
|
|
} else {
|
|
|
|
response.Header().Set("Content-Type", "application/octet-stream")
|
|
|
|
response.Header().Set("Content-Disposition", "attachment; filename=\"yggdrasil_session_pubkey.der\"")
|
|
|
|
_, _ = response.Write(asn1Bytes)
|
|
|
|
}
|
2021-02-26 02:45:45 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
// TODO: in v5 should be extracted into some ProfileProvider interface,
|
2023-12-12 01:35:08 +01:00
|
|
|
//
|
|
|
|
// which will encapsulate all logics, declared in this method
|
2021-02-26 02:45:45 +01:00
|
|
|
func (ctx *Skinsystem) getProfile(request *http.Request, proxy bool) (*profile, error) {
|
2020-01-01 23:42:45 +03:00
|
|
|
username := parseUsername(mux.Vars(request)["username"])
|
|
|
|
|
2021-02-26 02:45:45 +01:00
|
|
|
skin, err := ctx.SkinsRepo.FindSkinByUsername(username)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
2020-01-01 23:42:45 +03:00
|
|
|
|
2021-02-26 02:45:45 +01:00
|
|
|
profile := &profile{
|
2023-12-22 01:56:02 +01:00
|
|
|
Textures: &mojang.TexturesResponse{}, // Field must be initialized to avoid "null" after json encoding
|
2021-02-26 02:45:45 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
if skin != nil {
|
|
|
|
profile.Id = strings.Replace(skin.Uuid, "-", "", -1)
|
|
|
|
profile.Username = skin.Username
|
|
|
|
}
|
2020-01-01 23:42:45 +03:00
|
|
|
|
2023-12-22 01:56:02 +01:00
|
|
|
if skin != nil && skin.Url != "" {
|
2021-02-26 02:45:45 +01:00
|
|
|
profile.Textures.Skin = &mojang.SkinTexturesResponse{
|
|
|
|
Url: skin.Url,
|
2020-01-01 23:42:45 +03:00
|
|
|
}
|
|
|
|
|
2021-02-26 02:45:45 +01:00
|
|
|
if skin.IsSlim {
|
|
|
|
profile.Textures.Skin.Metadata = &mojang.SkinTexturesMetadata{
|
|
|
|
Model: "slim",
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
cape, _ := ctx.CapesRepo.FindCapeByUsername(username)
|
|
|
|
if cape != nil {
|
|
|
|
profile.CapeFile = cape.File
|
|
|
|
profile.Textures.Cape = &mojang.CapeTexturesResponse{
|
2020-04-21 16:24:30 +03:00
|
|
|
// Use statically http since the application doesn't support TLS
|
|
|
|
Url: "http://" + request.Host + "/cloaks/" + username,
|
2020-01-01 23:42:45 +03:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-02-26 02:45:45 +01:00
|
|
|
profile.MojangTextures = skin.MojangTextures
|
|
|
|
profile.MojangSignature = skin.MojangSignature
|
|
|
|
} else if proxy {
|
|
|
|
mojangProfile, err := ctx.MojangTexturesProvider.GetForUsername(username)
|
2024-01-10 01:42:10 +01:00
|
|
|
// If we at least know something about the user,
|
|
|
|
// then we can ignore an error and return profile without textures
|
2021-02-26 02:45:45 +01:00
|
|
|
if err != nil && profile.Id != "" {
|
|
|
|
return profile, nil
|
2020-01-01 23:42:45 +03:00
|
|
|
}
|
|
|
|
|
2021-02-26 02:45:45 +01:00
|
|
|
if err != nil || mojangProfile == nil {
|
2024-01-10 01:42:10 +01:00
|
|
|
if errors.Is(err, mojang.InvalidUsername) {
|
|
|
|
return nil, nil
|
|
|
|
}
|
|
|
|
|
2021-02-26 02:45:45 +01:00
|
|
|
return nil, err
|
2020-04-20 19:58:31 +03:00
|
|
|
}
|
2020-01-01 23:42:45 +03:00
|
|
|
|
2021-02-26 02:45:45 +01:00
|
|
|
decodedTextures, err := mojangProfile.DecodeTextures()
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
2020-01-01 23:42:45 +03:00
|
|
|
|
2021-02-26 02:45:45 +01:00
|
|
|
// There might be no textures property
|
|
|
|
if decodedTextures != nil {
|
|
|
|
profile.Textures = decodedTextures.Textures
|
|
|
|
}
|
2020-01-01 23:42:45 +03:00
|
|
|
|
2021-02-26 02:45:45 +01:00
|
|
|
var texturesProp *mojang.Property
|
|
|
|
for _, prop := range mojangProfile.Props {
|
|
|
|
if prop.Name == "textures" {
|
|
|
|
texturesProp = prop
|
|
|
|
break
|
|
|
|
}
|
2020-01-01 23:42:45 +03:00
|
|
|
}
|
2021-02-26 02:45:45 +01:00
|
|
|
|
|
|
|
if texturesProp != nil {
|
|
|
|
profile.MojangTextures = texturesProp.Value
|
|
|
|
profile.MojangSignature = texturesProp.Signature
|
2020-01-01 23:42:45 +03:00
|
|
|
}
|
|
|
|
|
2021-02-26 02:45:45 +01:00
|
|
|
// If user id is unknown at this point, then use values from Mojang profile
|
|
|
|
if profile.Id == "" {
|
|
|
|
profile.Id = mojangProfile.Id
|
|
|
|
profile.Username = mojangProfile.Name
|
|
|
|
}
|
2023-12-22 01:56:02 +01:00
|
|
|
} else if profile.Id != "" {
|
|
|
|
return profile, nil
|
2021-02-26 02:45:45 +01:00
|
|
|
} else {
|
|
|
|
return nil, nil
|
2020-01-01 23:42:45 +03:00
|
|
|
}
|
|
|
|
|
2021-02-26 02:45:45 +01:00
|
|
|
return profile, nil
|
2020-01-01 23:42:45 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
func parseUsername(username string) string {
|
|
|
|
return strings.TrimSuffix(username, ".png")
|
|
|
|
}
|