Squashed history
This commit is contained in:
commit
7f9392a5a6
25
.github/workflows/ci.yml
vendored
Normal file
25
.github/workflows/ci.yml
vendored
Normal file
@ -0,0 +1,25 @@
|
||||
name: CI
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [ main ]
|
||||
pull_request:
|
||||
branches: [ main ]
|
||||
|
||||
jobs:
|
||||
build:
|
||||
runs-on: ubuntu-latest
|
||||
defaults:
|
||||
run:
|
||||
working-directory: ./workers
|
||||
steps:
|
||||
- uses: actions/checkout@v3
|
||||
- name: Use Node.js version
|
||||
uses: actions/setup-node@v3
|
||||
with:
|
||||
node-version: 20.10.0
|
||||
cache: 'npm'
|
||||
cache-dependency-path: '**/package-lock.json'
|
||||
- run: npm ci
|
||||
- run: npm run build
|
||||
- run: npm test
|
||||
619
LICENSE
Normal file
619
LICENSE
Normal file
@ -0,0 +1,619 @@
|
||||
GNU AFFERO GENERAL PUBLIC LICENSE
|
||||
Version 3, 19 November 2007
|
||||
|
||||
Copyright (C) 2007 Free Software Foundation, Inc. <https://fsf.org/>
|
||||
Everyone is permitted to copy and distribute verbatim copies
|
||||
of this license document, but changing it is not allowed.
|
||||
|
||||
Preamble
|
||||
|
||||
The GNU Affero General Public License is a free, copyleft license for
|
||||
software and other kinds of works, specifically designed to ensure
|
||||
cooperation with the community in the case of network server software.
|
||||
|
||||
The licenses for most software and other practical works are designed
|
||||
to take away your freedom to share and change the works. By contrast,
|
||||
our General Public Licenses are intended to guarantee your freedom to
|
||||
share and change all versions of a program--to make sure it remains free
|
||||
software for all its users.
|
||||
|
||||
When we speak of free software, we are referring to freedom, not
|
||||
price. Our General Public Licenses are designed to make sure that you
|
||||
have the freedom to distribute copies of free software (and charge for
|
||||
them if you wish), that you receive source code or can get it if you
|
||||
want it, that you can change the software or use pieces of it in new
|
||||
free programs, and that you know you can do these things.
|
||||
|
||||
Developers that use our General Public Licenses protect your rights
|
||||
with two steps: (1) assert copyright on the software, and (2) offer
|
||||
you this License which gives you legal permission to copy, distribute
|
||||
and/or modify the software.
|
||||
|
||||
A secondary benefit of defending all users' freedom is that
|
||||
improvements made in alternate versions of the program, if they
|
||||
receive widespread use, become available for other developers to
|
||||
incorporate. Many developers of free software are heartened and
|
||||
encouraged by the resulting cooperation. However, in the case of
|
||||
software used on network servers, this result may fail to come about.
|
||||
The GNU General Public License permits making a modified version and
|
||||
letting the public access it on a server without ever releasing its
|
||||
source code to the public.
|
||||
|
||||
The GNU Affero General Public License is designed specifically to
|
||||
ensure that, in such cases, the modified source code becomes available
|
||||
to the community. It requires the operator of a network server to
|
||||
provide the source code of the modified version running there to the
|
||||
users of that server. Therefore, public use of a modified version, on
|
||||
a publicly accessible server, gives the public access to the source
|
||||
code of the modified version.
|
||||
|
||||
An older license, called the Affero General Public License and
|
||||
published by Affero, was designed to accomplish similar goals. This is
|
||||
a different license, not a version of the Affero GPL, but Affero has
|
||||
released a new version of the Affero GPL which permits relicensing under
|
||||
this license.
|
||||
|
||||
The precise terms and conditions for copying, distribution and
|
||||
modification follow.
|
||||
|
||||
TERMS AND CONDITIONS
|
||||
|
||||
0. Definitions.
|
||||
|
||||
"This License" refers to version 3 of the GNU Affero General Public License.
|
||||
|
||||
"Copyright" also means copyright-like laws that apply to other kinds of
|
||||
works, such as semiconductor masks.
|
||||
|
||||
"The Program" refers to any copyrightable work licensed under this
|
||||
License. Each licensee is addressed as "you". "Licensees" and
|
||||
"recipients" may be individuals or organizations.
|
||||
|
||||
To "modify" a work means to copy from or adapt all or part of the work
|
||||
in a fashion requiring copyright permission, other than the making of an
|
||||
exact copy. The resulting work is called a "modified version" of the
|
||||
earlier work or a work "based on" the earlier work.
|
||||
|
||||
A "covered work" means either the unmodified Program or a work based
|
||||
on the Program.
|
||||
|
||||
To "propagate" a work means to do anything with it that, without
|
||||
permission, would make you directly or secondarily liable for
|
||||
infringement under applicable copyright law, except executing it on a
|
||||
computer or modifying a private copy. Propagation includes copying,
|
||||
distribution (with or without modification), making available to the
|
||||
public, and in some countries other activities as well.
|
||||
|
||||
To "convey" a work means any kind of propagation that enables other
|
||||
parties to make or receive copies. Mere interaction with a user through
|
||||
a computer network, with no transfer of a copy, is not conveying.
|
||||
|
||||
An interactive user interface displays "Appropriate Legal Notices"
|
||||
to the extent that it includes a convenient and prominently visible
|
||||
feature that (1) displays an appropriate copyright notice, and (2)
|
||||
tells the user that there is no warranty for the work (except to the
|
||||
extent that warranties are provided), that licensees may convey the
|
||||
work under this License, and how to view a copy of this License. If
|
||||
the interface presents a list of user commands or options, such as a
|
||||
menu, a prominent item in the list meets this criterion.
|
||||
|
||||
1. Source Code.
|
||||
|
||||
The "source code" for a work means the preferred form of the work
|
||||
for making modifications to it. "Object code" means any non-source
|
||||
form of a work.
|
||||
|
||||
A "Standard Interface" means an interface that either is an official
|
||||
standard defined by a recognized standards body, or, in the case of
|
||||
interfaces specified for a particular programming language, one that
|
||||
is widely used among developers working in that language.
|
||||
|
||||
The "System Libraries" of an executable work include anything, other
|
||||
than the work as a whole, that (a) is included in the normal form of
|
||||
packaging a Major Component, but which is not part of that Major
|
||||
Component, and (b) serves only to enable use of the work with that
|
||||
Major Component, or to implement a Standard Interface for which an
|
||||
implementation is available to the public in source code form. A
|
||||
"Major Component", in this context, means a major essential component
|
||||
(kernel, window system, and so on) of the specific operating system
|
||||
(if any) on which the executable work runs, or a compiler used to
|
||||
produce the work, or an object code interpreter used to run it.
|
||||
|
||||
The "Corresponding Source" for a work in object code form means all
|
||||
the source code needed to generate, install, and (for an executable
|
||||
work) run the object code and to modify the work, including scripts to
|
||||
control those activities. However, it does not include the work's
|
||||
System Libraries, or general-purpose tools or generally available free
|
||||
programs which are used unmodified in performing those activities but
|
||||
which are not part of the work. For example, Corresponding Source
|
||||
includes interface definition files associated with source files for
|
||||
the work, and the source code for shared libraries and dynamically
|
||||
linked subprograms that the work is specifically designed to require,
|
||||
such as by intimate data communication or control flow between those
|
||||
subprograms and other parts of the work.
|
||||
|
||||
The Corresponding Source need not include anything that users
|
||||
can regenerate automatically from other parts of the Corresponding
|
||||
Source.
|
||||
|
||||
The Corresponding Source for a work in source code form is that
|
||||
same work.
|
||||
|
||||
2. Basic Permissions.
|
||||
|
||||
All rights granted under this License are granted for the term of
|
||||
copyright on the Program, and are irrevocable provided the stated
|
||||
conditions are met. This License explicitly affirms your unlimited
|
||||
permission to run the unmodified Program. The output from running a
|
||||
covered work is covered by this License only if the output, given its
|
||||
content, constitutes a covered work. This License acknowledges your
|
||||
rights of fair use or other equivalent, as provided by copyright law.
|
||||
|
||||
You may make, run and propagate covered works that you do not
|
||||
convey, without conditions so long as your license otherwise remains
|
||||
in force. You may convey covered works to others for the sole purpose
|
||||
of having them make modifications exclusively for you, or provide you
|
||||
with facilities for running those works, provided that you comply with
|
||||
the terms of this License in conveying all material for which you do
|
||||
not control copyright. Those thus making or running the covered works
|
||||
for you must do so exclusively on your behalf, under your direction
|
||||
and control, on terms that prohibit them from making any copies of
|
||||
your copyrighted material outside their relationship with you.
|
||||
|
||||
Conveying under any other circumstances is permitted solely under
|
||||
the conditions stated below. Sublicensing is not allowed; section 10
|
||||
makes it unnecessary.
|
||||
|
||||
3. Protecting Users' Legal Rights From Anti-Circumvention Law.
|
||||
|
||||
No covered work shall be deemed part of an effective technological
|
||||
measure under any applicable law fulfilling obligations under article
|
||||
11 of the WIPO copyright treaty adopted on 20 December 1996, or
|
||||
similar laws prohibiting or restricting circumvention of such
|
||||
measures.
|
||||
|
||||
When you convey a covered work, you waive any legal power to forbid
|
||||
circumvention of technological measures to the extent such circumvention
|
||||
is effected by exercising rights under this License with respect to
|
||||
the covered work, and you disclaim any intention to limit operation or
|
||||
modification of the work as a means of enforcing, against the work's
|
||||
users, your or third parties' legal rights to forbid circumvention of
|
||||
technological measures.
|
||||
|
||||
4. Conveying Verbatim Copies.
|
||||
|
||||
You may convey verbatim copies of the Program's source code as you
|
||||
receive it, in any medium, provided that you conspicuously and
|
||||
appropriately publish on each copy an appropriate copyright notice;
|
||||
keep intact all notices stating that this License and any
|
||||
non-permissive terms added in accord with section 7 apply to the code;
|
||||
keep intact all notices of the absence of any warranty; and give all
|
||||
recipients a copy of this License along with the Program.
|
||||
|
||||
You may charge any price or no price for each copy that you convey,
|
||||
and you may offer support or warranty protection for a fee.
|
||||
|
||||
5. Conveying Modified Source Versions.
|
||||
|
||||
You may convey a work based on the Program, or the modifications to
|
||||
produce it from the Program, in the form of source code under the
|
||||
terms of section 4, provided that you also meet all of these conditions:
|
||||
|
||||
a) The work must carry prominent notices stating that you modified
|
||||
it, and giving a relevant date.
|
||||
|
||||
b) The work must carry prominent notices stating that it is
|
||||
released under this License and any conditions added under section
|
||||
7. This requirement modifies the requirement in section 4 to
|
||||
"keep intact all notices".
|
||||
|
||||
c) You must license the entire work, as a whole, under this
|
||||
License to anyone who comes into possession of a copy. This
|
||||
License will therefore apply, along with any applicable section 7
|
||||
additional terms, to the whole of the work, and all its parts,
|
||||
regardless of how they are packaged. This License gives no
|
||||
permission to license the work in any other way, but it does not
|
||||
invalidate such permission if you have separately received it.
|
||||
|
||||
d) If the work has interactive user interfaces, each must display
|
||||
Appropriate Legal Notices; however, if the Program has interactive
|
||||
interfaces that do not display Appropriate Legal Notices, your
|
||||
work need not make them do so.
|
||||
|
||||
A compilation of a covered work with other separate and independent
|
||||
works, which are not by their nature extensions of the covered work,
|
||||
and which are not combined with it such as to form a larger program,
|
||||
in or on a volume of a storage or distribution medium, is called an
|
||||
"aggregate" if the compilation and its resulting copyright are not
|
||||
used to limit the access or legal rights of the compilation's users
|
||||
beyond what the individual works permit. Inclusion of a covered work
|
||||
in an aggregate does not cause this License to apply to the other
|
||||
parts of the aggregate.
|
||||
|
||||
6. Conveying Non-Source Forms.
|
||||
|
||||
You may convey a covered work in object code form under the terms
|
||||
of sections 4 and 5, provided that you also convey the
|
||||
machine-readable Corresponding Source under the terms of this License,
|
||||
in one of these ways:
|
||||
|
||||
a) Convey the object code in, or embodied in, a physical product
|
||||
(including a physical distribution medium), accompanied by the
|
||||
Corresponding Source fixed on a durable physical medium
|
||||
customarily used for software interchange.
|
||||
|
||||
b) Convey the object code in, or embodied in, a physical product
|
||||
(including a physical distribution medium), accompanied by a
|
||||
written offer, valid for at least three years and valid for as
|
||||
long as you offer spare parts or customer support for that product
|
||||
model, to give anyone who possesses the object code either (1) a
|
||||
copy of the Corresponding Source for all the software in the
|
||||
product that is covered by this License, on a durable physical
|
||||
medium customarily used for software interchange, for a price no
|
||||
more than your reasonable cost of physically performing this
|
||||
conveying of source, or (2) access to copy the
|
||||
Corresponding Source from a network server at no charge.
|
||||
|
||||
c) Convey individual copies of the object code with a copy of the
|
||||
written offer to provide the Corresponding Source. This
|
||||
alternative is allowed only occasionally and noncommercially, and
|
||||
only if you received the object code with such an offer, in accord
|
||||
with subsection 6b.
|
||||
|
||||
d) Convey the object code by offering access from a designated
|
||||
place (gratis or for a charge), and offer equivalent access to the
|
||||
Corresponding Source in the same way through the same place at no
|
||||
further charge. You need not require recipients to copy the
|
||||
Corresponding Source along with the object code. If the place to
|
||||
copy the object code is a network server, the Corresponding Source
|
||||
may be on a different server (operated by you or a third party)
|
||||
that supports equivalent copying facilities, provided you maintain
|
||||
clear directions next to the object code saying where to find the
|
||||
Corresponding Source. Regardless of what server hosts the
|
||||
Corresponding Source, you remain obligated to ensure that it is
|
||||
available for as long as needed to satisfy these requirements.
|
||||
|
||||
e) Convey the object code using peer-to-peer transmission, provided
|
||||
you inform other peers where the object code and Corresponding
|
||||
Source of the work are being offered to the general public at no
|
||||
charge under subsection 6d.
|
||||
|
||||
A separable portion of the object code, whose source code is excluded
|
||||
from the Corresponding Source as a System Library, need not be
|
||||
included in conveying the object code work.
|
||||
|
||||
A "User Product" is either (1) a "consumer product", which means any
|
||||
tangible personal property which is normally used for personal, family,
|
||||
or household purposes, or (2) anything designed or sold for incorporation
|
||||
into a dwelling. In determining whether a product is a consumer product,
|
||||
doubtful cases shall be resolved in favor of coverage. For a particular
|
||||
product received by a particular user, "normally used" refers to a
|
||||
typical or common use of that class of product, regardless of the status
|
||||
of the particular user or of the way in which the particular user
|
||||
actually uses, or expects or is expected to use, the product. A product
|
||||
is a consumer product regardless of whether the product has substantial
|
||||
commercial, industrial or non-consumer uses, unless such uses represent
|
||||
the only significant mode of use of the product.
|
||||
|
||||
"Installation Information" for a User Product means any methods,
|
||||
procedures, authorization keys, or other information required to install
|
||||
and execute modified versions of a covered work in that User Product from
|
||||
a modified version of its Corresponding Source. The information must
|
||||
suffice to ensure that the continued functioning of the modified object
|
||||
code is in no case prevented or interfered with solely because
|
||||
modification has been made.
|
||||
|
||||
If you convey an object code work under this section in, or with, or
|
||||
specifically for use in, a User Product, and the conveying occurs as
|
||||
part of a transaction in which the right of possession and use of the
|
||||
User Product is transferred to the recipient in perpetuity or for a
|
||||
fixed term (regardless of how the transaction is characterized), the
|
||||
Corresponding Source conveyed under this section must be accompanied
|
||||
by the Installation Information. But this requirement does not apply
|
||||
if neither you nor any third party retains the ability to install
|
||||
modified object code on the User Product (for example, the work has
|
||||
been installed in ROM).
|
||||
|
||||
The requirement to provide Installation Information does not include a
|
||||
requirement to continue to provide support service, warranty, or updates
|
||||
for a work that has been modified or installed by the recipient, or for
|
||||
the User Product in which it has been modified or installed. Access to a
|
||||
network may be denied when the modification itself materially and
|
||||
adversely affects the operation of the network or violates the rules and
|
||||
protocols for communication across the network.
|
||||
|
||||
Corresponding Source conveyed, and Installation Information provided,
|
||||
in accord with this section must be in a format that is publicly
|
||||
documented (and with an implementation available to the public in
|
||||
source code form), and must require no special password or key for
|
||||
unpacking, reading or copying.
|
||||
|
||||
7. Additional Terms.
|
||||
|
||||
"Additional permissions" are terms that supplement the terms of this
|
||||
License by making exceptions from one or more of its conditions.
|
||||
Additional permissions that are applicable to the entire Program shall
|
||||
be treated as though they were included in this License, to the extent
|
||||
that they are valid under applicable law. If additional permissions
|
||||
apply only to part of the Program, that part may be used separately
|
||||
under those permissions, but the entire Program remains governed by
|
||||
this License without regard to the additional permissions.
|
||||
|
||||
When you convey a copy of a covered work, you may at your option
|
||||
remove any additional permissions from that copy, or from any part of
|
||||
it. (Additional permissions may be written to require their own
|
||||
removal in certain cases when you modify the work.) You may place
|
||||
additional permissions on material, added by you to a covered work,
|
||||
for which you have or can give appropriate copyright permission.
|
||||
|
||||
Notwithstanding any other provision of this License, for material you
|
||||
add to a covered work, you may (if authorized by the copyright holders of
|
||||
that material) supplement the terms of this License with terms:
|
||||
|
||||
a) Disclaiming warranty or limiting liability differently from the
|
||||
terms of sections 15 and 16 of this License; or
|
||||
|
||||
b) Requiring preservation of specified reasonable legal notices or
|
||||
author attributions in that material or in the Appropriate Legal
|
||||
Notices displayed by works containing it; or
|
||||
|
||||
c) Prohibiting misrepresentation of the origin of that material, or
|
||||
requiring that modified versions of such material be marked in
|
||||
reasonable ways as different from the original version; or
|
||||
|
||||
d) Limiting the use for publicity purposes of names of licensors or
|
||||
authors of the material; or
|
||||
|
||||
e) Declining to grant rights under trademark law for use of some
|
||||
trade names, trademarks, or service marks; or
|
||||
|
||||
f) Requiring indemnification of licensors and authors of that
|
||||
material by anyone who conveys the material (or modified versions of
|
||||
it) with contractual assumptions of liability to the recipient, for
|
||||
any liability that these contractual assumptions directly impose on
|
||||
those licensors and authors.
|
||||
|
||||
All other non-permissive additional terms are considered "further
|
||||
restrictions" within the meaning of section 10. If the Program as you
|
||||
received it, or any part of it, contains a notice stating that it is
|
||||
governed by this License along with a term that is a further
|
||||
restriction, you may remove that term. If a license document contains
|
||||
a further restriction but permits relicensing or conveying under this
|
||||
License, you may add to a covered work material governed by the terms
|
||||
of that license document, provided that the further restriction does
|
||||
not survive such relicensing or conveying.
|
||||
|
||||
If you add terms to a covered work in accord with this section, you
|
||||
must place, in the relevant source files, a statement of the
|
||||
additional terms that apply to those files, or a notice indicating
|
||||
where to find the applicable terms.
|
||||
|
||||
Additional terms, permissive or non-permissive, may be stated in the
|
||||
form of a separately written license, or stated as exceptions;
|
||||
the above requirements apply either way.
|
||||
|
||||
8. Termination.
|
||||
|
||||
You may not propagate or modify a covered work except as expressly
|
||||
provided under this License. Any attempt otherwise to propagate or
|
||||
modify it is void, and will automatically terminate your rights under
|
||||
this License (including any patent licenses granted under the third
|
||||
paragraph of section 11).
|
||||
|
||||
However, if you cease all violation of this License, then your
|
||||
license from a particular copyright holder is reinstated (a)
|
||||
provisionally, unless and until the copyright holder explicitly and
|
||||
finally terminates your license, and (b) permanently, if the copyright
|
||||
holder fails to notify you of the violation by some reasonable means
|
||||
prior to 60 days after the cessation.
|
||||
|
||||
Moreover, your license from a particular copyright holder is
|
||||
reinstated permanently if the copyright holder notifies you of the
|
||||
violation by some reasonable means, this is the first time you have
|
||||
received notice of violation of this License (for any work) from that
|
||||
copyright holder, and you cure the violation prior to 30 days after
|
||||
your receipt of the notice.
|
||||
|
||||
Termination of your rights under this section does not terminate the
|
||||
licenses of parties who have received copies or rights from you under
|
||||
this License. If your rights have been terminated and not permanently
|
||||
reinstated, you do not qualify to receive new licenses for the same
|
||||
material under section 10.
|
||||
|
||||
9. Acceptance Not Required for Having Copies.
|
||||
|
||||
You are not required to accept this License in order to receive or
|
||||
run a copy of the Program. Ancillary propagation of a covered work
|
||||
occurring solely as a consequence of using peer-to-peer transmission
|
||||
to receive a copy likewise does not require acceptance. However,
|
||||
nothing other than this License grants you permission to propagate or
|
||||
modify any covered work. These actions infringe copyright if you do
|
||||
not accept this License. Therefore, by modifying or propagating a
|
||||
covered work, you indicate your acceptance of this License to do so.
|
||||
|
||||
10. Automatic Licensing of Downstream Recipients.
|
||||
|
||||
Each time you convey a covered work, the recipient automatically
|
||||
receives a license from the original licensors, to run, modify and
|
||||
propagate that work, subject to this License. You are not responsible
|
||||
for enforcing compliance by third parties with this License.
|
||||
|
||||
An "entity transaction" is a transaction transferring control of an
|
||||
organization, or substantially all assets of one, or subdividing an
|
||||
organization, or merging organizations. If propagation of a covered
|
||||
work results from an entity transaction, each party to that
|
||||
transaction who receives a copy of the work also receives whatever
|
||||
licenses to the work the party's predecessor in interest had or could
|
||||
give under the previous paragraph, plus a right to possession of the
|
||||
Corresponding Source of the work from the predecessor in interest, if
|
||||
the predecessor has it or can get it with reasonable efforts.
|
||||
|
||||
You may not impose any further restrictions on the exercise of the
|
||||
rights granted or affirmed under this License. For example, you may
|
||||
not impose a license fee, royalty, or other charge for exercise of
|
||||
rights granted under this License, and you may not initiate litigation
|
||||
(including a cross-claim or counterclaim in a lawsuit) alleging that
|
||||
any patent claim is infringed by making, using, selling, offering for
|
||||
sale, or importing the Program or any portion of it.
|
||||
|
||||
11. Patents.
|
||||
|
||||
A "contributor" is a copyright holder who authorizes use under this
|
||||
License of the Program or a work on which the Program is based. The
|
||||
work thus licensed is called the contributor's "contributor version".
|
||||
|
||||
A contributor's "essential patent claims" are all patent claims
|
||||
owned or controlled by the contributor, whether already acquired or
|
||||
hereafter acquired, that would be infringed by some manner, permitted
|
||||
by this License, of making, using, or selling its contributor version,
|
||||
but do not include claims that would be infringed only as a
|
||||
consequence of further modification of the contributor version. For
|
||||
purposes of this definition, "control" includes the right to grant
|
||||
patent sublicenses in a manner consistent with the requirements of
|
||||
this License.
|
||||
|
||||
Each contributor grants you a non-exclusive, worldwide, royalty-free
|
||||
patent license under the contributor's essential patent claims, to
|
||||
make, use, sell, offer for sale, import and otherwise run, modify and
|
||||
propagate the contents of its contributor version.
|
||||
|
||||
In the following three paragraphs, a "patent license" is any express
|
||||
agreement or commitment, however denominated, not to enforce a patent
|
||||
(such as an express permission to practice a patent or covenant not to
|
||||
sue for patent infringement). To "grant" such a patent license to a
|
||||
party means to make such an agreement or commitment not to enforce a
|
||||
patent against the party.
|
||||
|
||||
If you convey a covered work, knowingly relying on a patent license,
|
||||
and the Corresponding Source of the work is not available for anyone
|
||||
to copy, free of charge and under the terms of this License, through a
|
||||
publicly available network server or other readily accessible means,
|
||||
then you must either (1) cause the Corresponding Source to be so
|
||||
available, or (2) arrange to deprive yourself of the benefit of the
|
||||
patent license for this particular work, or (3) arrange, in a manner
|
||||
consistent with the requirements of this License, to extend the patent
|
||||
license to downstream recipients. "Knowingly relying" means you have
|
||||
actual knowledge that, but for the patent license, your conveying the
|
||||
covered work in a country, or your recipient's use of the covered work
|
||||
in a country, would infringe one or more identifiable patents in that
|
||||
country that you have reason to believe are valid.
|
||||
|
||||
If, pursuant to or in connection with a single transaction or
|
||||
arrangement, you convey, or propagate by procuring conveyance of, a
|
||||
covered work, and grant a patent license to some of the parties
|
||||
receiving the covered work authorizing them to use, propagate, modify
|
||||
or convey a specific copy of the covered work, then the patent license
|
||||
you grant is automatically extended to all recipients of the covered
|
||||
work and works based on it.
|
||||
|
||||
A patent license is "discriminatory" if it does not include within
|
||||
the scope of its coverage, prohibits the exercise of, or is
|
||||
conditioned on the non-exercise of one or more of the rights that are
|
||||
specifically granted under this License. You may not convey a covered
|
||||
work if you are a party to an arrangement with a third party that is
|
||||
in the business of distributing software, under which you make payment
|
||||
to the third party based on the extent of your activity of conveying
|
||||
the work, and under which the third party grants, to any of the
|
||||
parties who would receive the covered work from you, a discriminatory
|
||||
patent license (a) in connection with copies of the covered work
|
||||
conveyed by you (or copies made from those copies), or (b) primarily
|
||||
for and in connection with specific products or compilations that
|
||||
contain the covered work, unless you entered into that arrangement,
|
||||
or that patent license was granted, prior to 28 March 2007.
|
||||
|
||||
Nothing in this License shall be construed as excluding or limiting
|
||||
any implied license or other defenses to infringement that may
|
||||
otherwise be available to you under applicable patent law.
|
||||
|
||||
12. No Surrender of Others' Freedom.
|
||||
|
||||
If conditions are imposed on you (whether by court order, agreement or
|
||||
otherwise) that contradict the conditions of this License, they do not
|
||||
excuse you from the conditions of this License. If you cannot convey a
|
||||
covered work so as to satisfy simultaneously your obligations under this
|
||||
License and any other pertinent obligations, then as a consequence you may
|
||||
not convey it at all. For example, if you agree to terms that obligate you
|
||||
to collect a royalty for further conveying from those to whom you convey
|
||||
the Program, the only way you could satisfy both those terms and this
|
||||
License would be to refrain entirely from conveying the Program.
|
||||
|
||||
13. Remote Network Interaction; Use with the GNU General Public License.
|
||||
|
||||
Notwithstanding any other provision of this License, if you modify the
|
||||
Program, your modified version must prominently offer all users
|
||||
interacting with it remotely through a computer network (if your version
|
||||
supports such interaction) an opportunity to receive the Corresponding
|
||||
Source of your version by providing access to the Corresponding Source
|
||||
from a network server at no charge, through some standard or customary
|
||||
means of facilitating copying of software. This Corresponding Source
|
||||
shall include the Corresponding Source for any work covered by version 3
|
||||
of the GNU General Public License that is incorporated pursuant to the
|
||||
following paragraph.
|
||||
|
||||
Notwithstanding any other provision of this License, you have
|
||||
permission to link or combine any covered work with a work licensed
|
||||
under version 3 of the GNU General Public License into a single
|
||||
combined work, and to convey the resulting work. The terms of this
|
||||
License will continue to apply to the part which is the covered work,
|
||||
but the work with which it is combined will remain governed by version
|
||||
3 of the GNU General Public License.
|
||||
|
||||
14. Revised Versions of this License.
|
||||
|
||||
The Free Software Foundation may publish revised and/or new versions of
|
||||
the GNU Affero General Public License from time to time. Such new versions
|
||||
will be similar in spirit to the present version, but may differ in detail to
|
||||
address new problems or concerns.
|
||||
|
||||
Each version is given a distinguishing version number. If the
|
||||
Program specifies that a certain numbered version of the GNU Affero General
|
||||
Public License "or any later version" applies to it, you have the
|
||||
option of following the terms and conditions either of that numbered
|
||||
version or of any later version published by the Free Software
|
||||
Foundation. If the Program does not specify a version number of the
|
||||
GNU Affero General Public License, you may choose any version ever published
|
||||
by the Free Software Foundation.
|
||||
|
||||
If the Program specifies that a proxy can decide which future
|
||||
versions of the GNU Affero General Public License can be used, that proxy's
|
||||
public statement of acceptance of a version permanently authorizes you
|
||||
to choose that version for the Program.
|
||||
|
||||
Later license versions may give you additional or different
|
||||
permissions. However, no additional obligations are imposed on any
|
||||
author or copyright holder as a result of your choosing to follow a
|
||||
later version.
|
||||
|
||||
15. Disclaimer of Warranty.
|
||||
|
||||
THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY
|
||||
APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT
|
||||
HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY
|
||||
OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO,
|
||||
THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
|
||||
PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM
|
||||
IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF
|
||||
ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
|
||||
|
||||
16. Limitation of Liability.
|
||||
|
||||
IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
|
||||
WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS
|
||||
THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY
|
||||
GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE
|
||||
USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF
|
||||
DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD
|
||||
PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS),
|
||||
EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF
|
||||
SUCH DAMAGES.
|
||||
|
||||
17. Interpretation of Sections 15 and 16.
|
||||
|
||||
If the disclaimer of warranty and limitation of liability provided
|
||||
above cannot be given local legal effect according to their terms,
|
||||
reviewing courts shall apply local law that most closely approximates
|
||||
an absolute waiver of all civil liability in connection with the
|
||||
Program, unless a warranty or assumption of liability accompanies a
|
||||
copy of the Program in return for a fee.
|
||||
|
||||
END OF TERMS AND CONDITIONS
|
||||
10
README.md
Normal file
10
README.md
Normal file
@ -0,0 +1,10 @@
|
||||
# storage-manager-private
|
||||
|
||||
This repository provides services that are used by [Signal-Server](https://github.com/signalapp/Signal-Server) to manage the contents of object stores that back Signal's CDN system. These functions allow the server to delete objects, move objects between different buckets, and list objects.
|
||||
|
||||
|
||||
# License
|
||||
|
||||
Copyright 2024 Signal Messenger, LLC
|
||||
|
||||
Licensed under the [AGPLv3](LICENSE)
|
||||
13
workers/.editorconfig
Normal file
13
workers/.editorconfig
Normal file
@ -0,0 +1,13 @@
|
||||
# http://editorconfig.org
|
||||
root = true
|
||||
|
||||
[*]
|
||||
indent_style = tab
|
||||
tab_width = 2
|
||||
end_of_line = lf
|
||||
charset = utf-8
|
||||
trim_trailing_whitespace = true
|
||||
insert_final_newline = true
|
||||
|
||||
[*.yml]
|
||||
indent_style = space
|
||||
34
workers/.eslintrc
Normal file
34
workers/.eslintrc
Normal file
@ -0,0 +1,34 @@
|
||||
{
|
||||
"env": {
|
||||
"browser": true,
|
||||
"es2021": true
|
||||
},
|
||||
"extends": [
|
||||
"eslint:recommended",
|
||||
"plugin:@typescript-eslint/recommended"
|
||||
],
|
||||
"overrides": [
|
||||
],
|
||||
"parser": "@typescript-eslint/parser",
|
||||
"parserOptions": {
|
||||
"ecmaVersion": "latest",
|
||||
"sourceType": "module"
|
||||
},
|
||||
"plugins": [
|
||||
"@typescript-eslint"
|
||||
],
|
||||
"rules": {
|
||||
"semi": [2, "always"],
|
||||
"quotes": ["error", "single"],
|
||||
"no-unused-vars": "off",
|
||||
"prefer-const": ["error", {"destructuring": "all"}],
|
||||
"@typescript-eslint/no-unused-vars": [
|
||||
"warn",
|
||||
{
|
||||
"argsIgnorePattern": "^_",
|
||||
"varsIgnorePattern": "^_",
|
||||
"caughtErrorsIgnorePattern": "^_"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
176
workers/.gitignore
vendored
Normal file
176
workers/.gitignore
vendored
Normal file
@ -0,0 +1,176 @@
|
||||
# Logs
|
||||
|
||||
logs
|
||||
_.log
|
||||
npm-debug.log_
|
||||
yarn-debug.log*
|
||||
yarn-error.log*
|
||||
lerna-debug.log*
|
||||
.pnpm-debug.log*
|
||||
|
||||
# Diagnostic reports (https://nodejs.org/api/report.html)
|
||||
|
||||
report.[0-9]_.[0-9]_.[0-9]_.[0-9]_.json
|
||||
|
||||
# Runtime data
|
||||
|
||||
pids
|
||||
_.pid
|
||||
_.seed
|
||||
\*.pid.lock
|
||||
|
||||
# Directory for instrumented libs generated by jscoverage/JSCover
|
||||
|
||||
lib-cov
|
||||
|
||||
# Coverage directory used by tools like istanbul
|
||||
|
||||
coverage
|
||||
\*.lcov
|
||||
|
||||
# nyc test coverage
|
||||
|
||||
.nyc_output
|
||||
|
||||
# Grunt intermediate storage (https://gruntjs.com/creating-plugins#storing-task-files)
|
||||
|
||||
.grunt
|
||||
|
||||
# Bower dependency directory (https://bower.io/)
|
||||
|
||||
bower_components
|
||||
|
||||
# node-waf configuration
|
||||
|
||||
.lock-wscript
|
||||
|
||||
# Compiled binary addons (https://nodejs.org/api/addons.html)
|
||||
|
||||
build/Release
|
||||
|
||||
# Dependency directories
|
||||
|
||||
node_modules/
|
||||
jspm_packages/
|
||||
|
||||
# Snowpack dependency directory (https://snowpack.dev/)
|
||||
|
||||
web_modules/
|
||||
|
||||
# TypeScript cache
|
||||
|
||||
\*.tsbuildinfo
|
||||
|
||||
# Optional npm cache directory
|
||||
|
||||
.npm
|
||||
|
||||
# Optional eslint cache
|
||||
|
||||
.eslintcache
|
||||
|
||||
# Optional stylelint cache
|
||||
|
||||
.stylelintcache
|
||||
|
||||
# Microbundle cache
|
||||
|
||||
.rpt2_cache/
|
||||
.rts2_cache_cjs/
|
||||
.rts2_cache_es/
|
||||
.rts2_cache_umd/
|
||||
|
||||
# Optional REPL history
|
||||
|
||||
.node_repl_history
|
||||
|
||||
# Output of 'npm pack'
|
||||
|
||||
\*.tgz
|
||||
|
||||
# Yarn Integrity file
|
||||
|
||||
.yarn-integrity
|
||||
|
||||
# dotenv environment variable files
|
||||
|
||||
.env
|
||||
.env.development.local
|
||||
.env.test.local
|
||||
.env.production.local
|
||||
.env.local
|
||||
|
||||
# parcel-bundler cache (https://parceljs.org/)
|
||||
|
||||
.cache
|
||||
.parcel-cache
|
||||
|
||||
# Next.js build output
|
||||
|
||||
.next
|
||||
out
|
||||
|
||||
# Nuxt.js build / generate output
|
||||
|
||||
.nuxt
|
||||
dist
|
||||
|
||||
# Gatsby files
|
||||
|
||||
.cache/
|
||||
|
||||
# Comment in the public line in if your project uses Gatsby and not Next.js
|
||||
|
||||
# https://nextjs.org/blog/next-9-1#public-directory-support
|
||||
|
||||
# public
|
||||
|
||||
# vuepress build output
|
||||
|
||||
.vuepress/dist
|
||||
|
||||
# vuepress v2.x temp and cache directory
|
||||
|
||||
.temp
|
||||
.cache
|
||||
|
||||
# Docusaurus cache and generated files
|
||||
|
||||
.docusaurus
|
||||
|
||||
# Serverless directories
|
||||
|
||||
.serverless/
|
||||
|
||||
# FuseBox cache
|
||||
|
||||
.fusebox/
|
||||
|
||||
# DynamoDB Local files
|
||||
|
||||
.dynamodb/
|
||||
|
||||
# TernJS port file
|
||||
|
||||
.tern-port
|
||||
|
||||
# Stores VSCode versions used for testing VSCode extensions
|
||||
|
||||
.vscode-test
|
||||
|
||||
# yarn v2
|
||||
|
||||
.yarn/cache
|
||||
.yarn/unplugged
|
||||
.yarn/build-state.yml
|
||||
.yarn/install-state.gz
|
||||
.pnp.\*
|
||||
|
||||
# wrangler project
|
||||
|
||||
.dev.vars
|
||||
.wrangler/
|
||||
|
||||
# webstorm
|
||||
|
||||
.idea
|
||||
1
workers/.nvmrc
Normal file
1
workers/.nvmrc
Normal file
@ -0,0 +1 @@
|
||||
20.10.0
|
||||
6
workers/.prettierrc
Normal file
6
workers/.prettierrc
Normal file
@ -0,0 +1,6 @@
|
||||
{
|
||||
"printWidth": 140,
|
||||
"singleQuote": true,
|
||||
"semi": true,
|
||||
"useTabs": true
|
||||
}
|
||||
37
workers/README.md
Normal file
37
workers/README.md
Normal file
@ -0,0 +1,37 @@
|
||||
# Overview
|
||||
|
||||
This directory provides a storage-manager built on [Cloudflare workers](https://developers.cloudflare.com/workers/) that manages objects stored on [Cloudflare R2](https://developers.cloudflare.com/r2/)
|
||||
|
||||
# Building
|
||||
You'll need [Node.js](https://nodejs.org/). If you use [nvm](https://github.com/creationix/nvm) run
|
||||
```
|
||||
nvm use
|
||||
```
|
||||
|
||||
To install dependencies,
|
||||
```
|
||||
npm install
|
||||
```
|
||||
|
||||
In order to deploy to Cloudflare or use non-local development mode, use the [`wrangler`](https://developers.cloudflare.com/workers/wrangler/install-and-update/) utility. Follow those instructions to authenticate with your Cloudflare account.
|
||||
|
||||
# Testing
|
||||
|
||||
To run a development server you can interact with over `localhost`:
|
||||
```
|
||||
npx wrangler dev
|
||||
```
|
||||
|
||||
To run unit tests,
|
||||
```
|
||||
npm test
|
||||
```
|
||||
|
||||
# Deploying
|
||||
|
||||
## One time setup
|
||||
Create R2 buckets and update the bindings in `wrangler.toml`, then:
|
||||
|
||||
```
|
||||
wrangler deploy -e <staging|production>
|
||||
```
|
||||
3933
workers/package-lock.json
generated
Normal file
3933
workers/package-lock.json
generated
Normal file
File diff suppressed because it is too large
Load Diff
25
workers/package.json
Normal file
25
workers/package.json
Normal file
@ -0,0 +1,25 @@
|
||||
{
|
||||
"name": "storage-manager",
|
||||
"version": "0.1.0",
|
||||
"type": "module",
|
||||
"devDependencies": {
|
||||
"@cloudflare/workers-types": "^4.20230419.0",
|
||||
"@typescript-eslint/eslint-plugin": "^6.10.0",
|
||||
"@typescript-eslint/parser": "^6.10.0",
|
||||
"eslint": "^8.53.0",
|
||||
"typescript": "^5.0.4",
|
||||
"vitest": "^0.34.6",
|
||||
"wrangler": "^3.0.0"
|
||||
},
|
||||
"dependencies": {
|
||||
"itty-router": "^4.0.23"
|
||||
},
|
||||
"private": true,
|
||||
"scripts": {
|
||||
"start": "wrangler dev",
|
||||
"deploy": "wrangler publish",
|
||||
"build": "wrangler deploy --dry-run --outdir=dist",
|
||||
"pretest": "wrangler deploy --dry-run --outdir=dist",
|
||||
"test": "vitest"
|
||||
}
|
||||
}
|
||||
51
workers/src/encrypt.test.ts
Normal file
51
workers/src/encrypt.test.ts
Normal file
@ -0,0 +1,51 @@
|
||||
// Copyright 2024 Signal Messenger, LLC
|
||||
// SPDX-License-Identifier: AGPL-3.0-only
|
||||
|
||||
import { describe, expect, it } from 'vitest';
|
||||
import { randBytes, readableStreamFrom, readAll, webcryptoAuthenticateAndDecrypt } from './testutil';
|
||||
import { Encrypter, streamEncrypt } from './encrypt';
|
||||
|
||||
describe('streamEncrypt', () => {
|
||||
const keyBytes: Uint8Array = randBytes(32);
|
||||
const hmacKey = randBytes(32);
|
||||
const iv = randBytes(16);
|
||||
|
||||
it.each([1, 3, 113])('handles chunks of size %s', async (chunkSize) => {
|
||||
const plaintext = randBytes(1763);
|
||||
const encrypter = await Encrypter.create(iv, hmacKey, keyBytes);
|
||||
|
||||
const { readable: source, writable: inp } = new TransformStream();
|
||||
const { readable: out, writable: dst } = new TransformStream();
|
||||
const [writePromise, readPromise] = [streamEncrypt(encrypter, source, dst, 128), readAll(out)];
|
||||
|
||||
const writer = inp.getWriter();
|
||||
for (let i = 0; i < plaintext.length; i += chunkSize) {
|
||||
await writer.write(plaintext.subarray(i, i + chunkSize));
|
||||
}
|
||||
await writer.close();
|
||||
|
||||
await writePromise;
|
||||
const encrypted = await readPromise;
|
||||
const decrypted = await webcryptoAuthenticateAndDecrypt(iv, keyBytes, hmacKey, encrypted);
|
||||
|
||||
expect(encrypted.length).toBe(encrypter.encryptedLength(plaintext.length));
|
||||
expect(decrypted).toEqual(plaintext);
|
||||
});
|
||||
|
||||
it.each([
|
||||
0, 16, 17, 32, 1023, 1024, 1025, 1024 * 3 + 7
|
||||
])('encrypts a single chunk of size %s', async (plaintextLength: number) => {
|
||||
const plaintext = randBytes(plaintextLength);
|
||||
const encrypter = await Encrypter.create(iv, hmacKey, keyBytes);
|
||||
|
||||
|
||||
const source = readableStreamFrom(plaintext);
|
||||
const { readable: actual, writable: dst } = new TransformStream();
|
||||
const encrypt = streamEncrypt(encrypter, source, dst, 1024);
|
||||
const ciphertext = await readAll(actual);
|
||||
const decrypted = await webcryptoAuthenticateAndDecrypt(iv, keyBytes, hmacKey, ciphertext);
|
||||
await encrypt;
|
||||
expect(decrypted).toEqual(plaintext);
|
||||
expect(ciphertext.length).toBe(encrypter.encryptedLength(plaintextLength));
|
||||
});
|
||||
});
|
||||
159
workers/src/encrypt.ts
Normal file
159
workers/src/encrypt.ts
Normal file
@ -0,0 +1,159 @@
|
||||
// Copyright 2024 Signal Messenger, LLC
|
||||
// SPDX-License-Identifier: AGPL-3.0-only
|
||||
|
||||
import crypto from 'node:crypto';
|
||||
|
||||
// @ts-expect-error crypto is available both in node and workers
|
||||
const subtle = globalThis.crypto.subtle;
|
||||
|
||||
// Maximum plaintext length where the output length (including a 16-byte IV, 32-byte HMAC, and up to 16 extra padding
|
||||
// bytes) will fit in a Number.MAX_SAFE_INTEGER
|
||||
const MAX_PLAINTEXT_LENGTH = Number.MAX_SAFE_INTEGER - 32 - 16 - 16;
|
||||
|
||||
/**
|
||||
* Writes IV || AES-CBC-256(plaintext) || HMAC-SHA-256(IV || ciphertext)
|
||||
*
|
||||
* The underlying webcrypto APIs do not provide streaming AES. This class builds streaming AES-CBC over one-shot, with
|
||||
* the caveat that all but the last block must be provided as a multiple of the block size (16 bytes).
|
||||
*/
|
||||
export class Encrypter {
|
||||
hmac: crypto.Hmac;
|
||||
iv: Uint8Array;
|
||||
aesKey: CryptoKey;
|
||||
|
||||
constructor(iv: Uint8Array, hmac: crypto.Hmac, aesKey: CryptoKey) {
|
||||
if (iv.length !== 16) {
|
||||
throw new Error('invalid iv length ' + iv.length);
|
||||
}
|
||||
this.hmac = hmac;
|
||||
this.aesKey = aesKey;
|
||||
this.iv = new Uint8Array(16);
|
||||
this.iv.set(iv);
|
||||
}
|
||||
|
||||
static async create(iv: Uint8Array, hmacKey: Uint8Array, aesKey: Uint8Array): Promise<Encrypter> {
|
||||
return new Encrypter(
|
||||
iv,
|
||||
crypto.createHmac('sha256', hmacKey),
|
||||
await subtle.importKey('raw', aesKey, 'AES-CBC', false, ['encrypt']));
|
||||
}
|
||||
|
||||
encryptedLength(plaintextLength: number): number {
|
||||
if (plaintextLength > MAX_PLAINTEXT_LENGTH) {
|
||||
throw new Error('plaintext length too large' + plaintextLength);
|
||||
}
|
||||
// AES-256 has 16-byte block size, and always adds a block if the plaintext is a multiple of the block size
|
||||
const numBlocks = Math.ceil((plaintextLength + 1) / 16);
|
||||
return this.iv.length +
|
||||
(numBlocks * 16) + // AES-256 encrypted data
|
||||
32; // hmac-sha256(IV || encrypted)
|
||||
}
|
||||
|
||||
/**
|
||||
* Initialize the encrypter
|
||||
*
|
||||
* Writes the iv to dst
|
||||
*
|
||||
* @param dst The output stream for the encrypter
|
||||
*/
|
||||
async init(dst: WritableStreamDefaultWriter<Uint8Array>) {
|
||||
await dst.write(this.iv);
|
||||
this.hmac.update(this.iv);
|
||||
}
|
||||
|
||||
/**
|
||||
* Encrypt and write one or more 16-byte blocks of plaintext
|
||||
*
|
||||
* @param dst The output stream for the encrypter where the encrypted plaintext will be written
|
||||
* @param plaintext The plaintext to encrypt
|
||||
*/
|
||||
async encrypt(dst: WritableStreamDefaultWriter<Uint8Array>, plaintext: Uint8Array) {
|
||||
if (plaintext.length % 16 !== 0) {
|
||||
throw new Error('All but final block must be multiple of block size (16)');
|
||||
}
|
||||
|
||||
let encrypted = new Uint8Array(await subtle.encrypt({ name: 'AES-CBC', iv: this.iv }, this.aesKey, plaintext));
|
||||
|
||||
if (encrypted.length !== plaintext.length + 16) {
|
||||
// sanity check: we should always end up with an extra padding block
|
||||
throw new Error(`Unexpected AES output length ${encrypted.length} instead of ${plaintext.length + 16}`);
|
||||
}
|
||||
|
||||
// Since plaintext is a multiple of block size, the PKCS#7 padding added to the plaintext will always add a 16-byte
|
||||
// block. We can trim this off since we don't want any padding until the final block.
|
||||
encrypted = encrypted.subarray(0, encrypted.length - 16);
|
||||
|
||||
// In CBC mode, the iv for the next block is the previous block
|
||||
this.iv.set(encrypted.subarray(encrypted.length - 16));
|
||||
|
||||
await dst.write(encrypted);
|
||||
this.hmac.update(encrypted);
|
||||
}
|
||||
|
||||
/**
|
||||
* Finish writing
|
||||
*
|
||||
* Encrypts and writes the remaining plaintext if provided, and writes the HMAC of the IV and encrypted bytes
|
||||
*
|
||||
* @param dst The output stream for the encrypter
|
||||
* @param plaintext If present, plaintext to encrypt and write to dst
|
||||
*/
|
||||
async finish(dst: WritableStreamDefaultWriter<Uint8Array>, plaintext: Uint8Array | undefined) {
|
||||
const encrypted = new Uint8Array(await subtle.encrypt({ name: 'AES-CBC', iv: this.iv }, this.aesKey, plaintext));
|
||||
await dst.write(encrypted);
|
||||
this.hmac.update(encrypted);
|
||||
await dst.write(this.hmac.digest());
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Encrypt the source stream and write it to the destination stream.
|
||||
*
|
||||
* Writes:
|
||||
* IV || AES-CBC-256(source) || HMAC-SHA256(IV || AES-CBC-256(source))
|
||||
*/
|
||||
export async function streamEncrypt(
|
||||
encrypter: Encrypter,
|
||||
source: ReadableStream<Uint8Array>,
|
||||
dst: WritableStream<Uint8Array>,
|
||||
bufferSize?: number) {
|
||||
|
||||
bufferSize = bufferSize || 1024 * 1024;
|
||||
if (bufferSize % 16 !== 0) {
|
||||
throw new Error('bufferSize must be a multiple of AES-CBC-256 blockSize (16)');
|
||||
}
|
||||
|
||||
// This could be cleaned up a little bit with use of the TransformStream API, however cloudflare workers does not
|
||||
// currently support Transforms other than IdentityTransforms.
|
||||
const writer = dst.getWriter();
|
||||
try {
|
||||
// write the IV
|
||||
await encrypter.init(writer);
|
||||
|
||||
// we'll buffer up to 1MiB before encrypting and flushing
|
||||
const plaintext = new Uint8Array(bufferSize);
|
||||
let offset = 0;
|
||||
for await (const sourceChunk of source) {
|
||||
let chunk: Uint8Array | null = sourceChunk;
|
||||
|
||||
// Keep writing the chunk until it has all made it into the writer, or it has been buffered into `plaintext`
|
||||
do {
|
||||
const amtToCopy = Math.min(plaintext.length - offset, chunk.length);
|
||||
plaintext.set(chunk.subarray(0, amtToCopy), offset);
|
||||
offset += amtToCopy;
|
||||
if (offset === plaintext.length) {
|
||||
// plaintext buffer is full, encrypt and flush it down
|
||||
await encrypter.encrypt(writer, plaintext);
|
||||
offset = 0;
|
||||
}
|
||||
// If there's more left in the chunk, trim it and keep going.
|
||||
chunk = amtToCopy < chunk.length ? chunk.subarray(amtToCopy) : null;
|
||||
} while (chunk !== null);
|
||||
}
|
||||
|
||||
// write whatever is left and the hmac
|
||||
await encrypter.finish(writer, plaintext.subarray(0, offset));
|
||||
} finally {
|
||||
await writer.close();
|
||||
}
|
||||
}
|
||||
283
workers/src/index.test.ts
Normal file
283
workers/src/index.test.ts
Normal file
@ -0,0 +1,283 @@
|
||||
// Copyright 2024 Signal Messenger, LLC
|
||||
// SPDX-License-Identifier: AGPL-3.0-only
|
||||
|
||||
import { afterAll, afterEach, beforeAll, describe, expect, it } from 'vitest';
|
||||
import { unstable_dev, UnstableDevWorker } from 'wrangler';
|
||||
import { randBytes, randomishBytes, webcryptoAuthenticateAndDecrypt } from './testutil';
|
||||
import { ListResponse } from './index';
|
||||
|
||||
|
||||
let worker: UnstableDevWorker;
|
||||
let r2Worker: UnstableDevWorker;
|
||||
beforeAll(async () => {
|
||||
worker = await unstable_dev('src/index.ts', {
|
||||
experimental: { disableExperimentalWarning: true }
|
||||
});
|
||||
r2Worker = await unstable_dev('src/r2TestWorker.ts', {
|
||||
experimental: { disableExperimentalWarning: true }
|
||||
});
|
||||
});
|
||||
|
||||
afterEach(async () => {
|
||||
await r2Clear('attachments');
|
||||
await r2Clear('backups');
|
||||
});
|
||||
|
||||
afterAll(async () => {
|
||||
await worker.stop();
|
||||
await r2Worker.stop();
|
||||
});
|
||||
|
||||
async function r2Clear(bucketName: string): Promise<void> {
|
||||
const response = await r2Worker.fetch(`http://${r2Worker.address}:${r2Worker.port}/${bucketName}`, { method: 'DELETE' });
|
||||
if (response.status !== 200) {
|
||||
throw new Error(`error ${response.status} : ${response.statusText}`);
|
||||
}
|
||||
}
|
||||
|
||||
async function r2Put(bucketName: string, key: string, content: string | Uint8Array): Promise<number> {
|
||||
const url = `http://${r2Worker.address}:${r2Worker.port}/${bucketName}/${key}`;
|
||||
const response = await r2Worker.fetch(url, {
|
||||
method: 'PUT',
|
||||
body: content,
|
||||
headers: {
|
||||
'Content-Length': `${content.length}`
|
||||
}
|
||||
});
|
||||
if (response.status !== 200) {
|
||||
throw new Error(`error ${response.status} : ${response.statusText}`);
|
||||
}
|
||||
return response.status;
|
||||
}
|
||||
|
||||
async function r2Get(bucketName: string, key: string): Promise<Uint8Array | null> {
|
||||
const url = `http://${r2Worker.address}:${r2Worker.port}/${bucketName}/${key}`;
|
||||
const response = await r2Worker.fetch(url, { method: 'GET' });
|
||||
if (response.status == 404) {
|
||||
return null;
|
||||
}
|
||||
if (response.status != 200) {
|
||||
throw new Error(`error ${response.status} : ${response.statusText}`);
|
||||
}
|
||||
return new Uint8Array(await response.arrayBuffer());
|
||||
}
|
||||
|
||||
describe('deletes', () => {
|
||||
it.each([
|
||||
'attachments',
|
||||
'backups'
|
||||
])('delete from %s', async (bucketName: string) => {
|
||||
await r2Put(bucketName, 'abc', 'test');
|
||||
expect(await r2Get(bucketName, 'abc')).toStrictEqual(new TextEncoder().encode('test'));
|
||||
|
||||
const res = await worker.fetch(`http://localhost/${bucketName}/abc`, { method: 'DELETE' });
|
||||
expect(res.status).toBe(200);
|
||||
expect(await res.json()).toEqual({ bytesDeleted: 4 });
|
||||
expect(await r2Get(bucketName, 'abc')).toBeNull();
|
||||
});
|
||||
|
||||
it('succeeds on missing objects', async () => {
|
||||
const res = await worker.fetch('http://localhost/attachments/fake', { method: 'DELETE' });
|
||||
expect(res.status).toBe(200);
|
||||
expect(await res.json()).toEqual({ bytesDeleted: 0 });
|
||||
});
|
||||
|
||||
it('handles on objects with / in the name', async () => {
|
||||
await r2Put('attachments', 'abc/def', 'test');
|
||||
const res = await worker.fetch('http://localhost/attachments/abc/def', { method: 'DELETE' });
|
||||
expect(res.status).toBe(200);
|
||||
expect(await res.json()).toEqual({ bytesDeleted: 4 });
|
||||
expect(await r2Get('attachments', 'abc/def')).toBeNull();
|
||||
});
|
||||
|
||||
});
|
||||
|
||||
describe('list', () => {
|
||||
const prefix = 'myBackupId/media';
|
||||
|
||||
async function addObjects(prefix: string, numObjects: number, content: string): Promise<string[]> {
|
||||
const keys = [...Array(numObjects).keys()].map(i => `${prefix}/${i}`);
|
||||
for (const key of keys) {
|
||||
await r2Put('backups', key, content);
|
||||
}
|
||||
return keys;
|
||||
}
|
||||
|
||||
it('lists all objects', async () => {
|
||||
const keys = await addObjects(prefix, 5, 'test');
|
||||
|
||||
const response = await worker.fetch(`http://localhost/backups?prefix=${prefix}&limit=5`, { method: 'GET' });
|
||||
expect(response.status).toBe(200);
|
||||
const res = await response.json() as ListResponse;
|
||||
expect(res.cursor).toBeUndefined();
|
||||
expect(res.objects).toHaveLength(5);
|
||||
expect(res.objects.map(obj => obj.key)).toEqual(keys);
|
||||
expect(res.objects.map(obj => obj.size).every(n => n === 4)).toBeTruthy();
|
||||
});
|
||||
|
||||
it('limit larger than numObjects', async () => {
|
||||
await addObjects(prefix, 5, 'test');
|
||||
const response = await worker.fetch(`http://localhost/backups/?prefix=${prefix}&limit=10`, { method: 'GET' });
|
||||
expect(response.status).toBe(200);
|
||||
const res = await response.json() as ListResponse;
|
||||
expect(res.cursor).toBeUndefined();
|
||||
expect(res.objects).toHaveLength(5);
|
||||
});
|
||||
|
||||
it('pages results', async () => {
|
||||
const keys = await addObjects(prefix, 5, 'test');
|
||||
|
||||
let response = await worker.fetch(`http://localhost/backups?prefix=${prefix}&limit=3`, { method: 'GET' });
|
||||
expect(response.status).toBe(200);
|
||||
let res = await response.json() as ListResponse;
|
||||
expect(res.cursor).toBeTruthy();
|
||||
expect(res.objects).toHaveLength(3);
|
||||
expect(res.objects.map(obj => obj.key)).toEqual(keys.slice(0, 3));
|
||||
|
||||
response = await worker.fetch(`http://localhost/backups/?prefix=${prefix}&limit=3&cursor=${res.cursor}`, { method: 'GET' });
|
||||
expect(response.status).toBe(200);
|
||||
res = await response.json() as ListResponse;
|
||||
expect(res.cursor).toBeFalsy();
|
||||
expect(res.objects).toHaveLength(2);
|
||||
expect(res.objects.map(obj => obj.key)).toEqual(keys.slice(3));
|
||||
});
|
||||
|
||||
it('handles url-encoded query parameters', async () => {
|
||||
await addObjects('myBackupId==/m/edia', 5, 'test');
|
||||
await addObjects('myBackUpId==/m/edia2', 10, 'test');
|
||||
|
||||
const url = `http://${r2Worker.address}:${r2Worker.port}/backups`;
|
||||
await r2Worker.fetch(url, { method: 'GET' });
|
||||
|
||||
const response = await worker.fetch(
|
||||
`http://localhost/backups/?prefix=${encodeURIComponent('myBackupId==/m/edia')}&limit=10`,
|
||||
{ method: 'GET' });
|
||||
expect(response.status).toBe(200);
|
||||
const res = await response.json() as ListResponse;
|
||||
expect(res.cursor).toBeUndefined();
|
||||
expect(res.objects).toHaveLength(5);
|
||||
});
|
||||
});
|
||||
|
||||
describe('usage', async () => {
|
||||
it('calculates usage', async () => {
|
||||
let total = 0;
|
||||
for (let i = 0; i < 100; i++) {
|
||||
await r2Put('backups', `prefix1/${i}`, randBytes(i));
|
||||
await r2Put('backups', `prefix2/${i}`, randBytes(i));
|
||||
total += i;
|
||||
}
|
||||
const response = await worker.fetch('http://localhost/usage?prefix=prefix1', { method: 'GET' });
|
||||
expect(response.status).toBe(200);
|
||||
const { bytesUsed, numObjects } = await response.json() as { bytesUsed: number, numObjects: number };
|
||||
expect(bytesUsed).toBe(total);
|
||||
expect(numObjects).toBe(100);
|
||||
});
|
||||
|
||||
it('handles 0 bytesUsed', async () => {
|
||||
const response = await worker.fetch('http://localhost/usage?prefix=prefix1', { method: 'GET' });
|
||||
expect(response.status).toBe(200);
|
||||
const { bytesUsed, numObjects } = await response.json() as { bytesUsed: number, numObjects: number };
|
||||
expect(bytesUsed).toBe(0);
|
||||
expect(numObjects).toBe(0);
|
||||
});
|
||||
|
||||
const pagingParams = [1, 3, 5, 10, 50, 100, 113]
|
||||
.flatMap(i => [1, 3, 5, 50, 113].map(j => ({ numObjects: i, limit: j })));
|
||||
it.each(pagingParams)('handles paging %s', async (params) => {
|
||||
let total = 0;
|
||||
for (let i = 0; i < params.numObjects; i++) {
|
||||
await r2Put('backups', `prefix1/${i}`, randBytes(i));
|
||||
total += i;
|
||||
}
|
||||
const response = await worker.fetch(`http://localhost/usage?prefix=prefix1&limit=${params.limit}`, { method: 'GET' });
|
||||
expect(response.status).toBe(200);
|
||||
const { bytesUsed, numObjects } = await response.json() as { bytesUsed: number, numObjects: number };
|
||||
expect(bytesUsed).toBe(total);
|
||||
expect(numObjects).toBe(params.numObjects);
|
||||
});
|
||||
});
|
||||
|
||||
describe('copy', () => {
|
||||
const key = randBytes(32);
|
||||
const hmacKey = randBytes(32);
|
||||
const iv = randBytes(16);
|
||||
const plaintext = randBytes(1024 * 3 + 7);
|
||||
|
||||
function validRequest(source: Uint8Array = plaintext) {
|
||||
return {
|
||||
encryptionKey: Buffer.from(key).toString('base64'),
|
||||
hmacKey: Buffer.from(hmacKey).toString('base64'),
|
||||
iv: Buffer.from(iv).toString('base64'),
|
||||
source: 'abc',
|
||||
expectedSourceLength: source.length,
|
||||
dst: 'my/abc'
|
||||
};
|
||||
}
|
||||
|
||||
it.each(Object.keys(validRequest()))('rejects missing %s', async (missingProp: string) => {
|
||||
const request: Record<string, unknown> = validRequest();
|
||||
delete request[missingProp];
|
||||
const body = JSON.stringify(request);
|
||||
const res = await worker.fetch('http://localhost/copy', {
|
||||
method: 'PUT',
|
||||
body: body,
|
||||
headers: { 'Content-Length': body.length.toString() }
|
||||
});
|
||||
expect(res.status, await res.text()).toBe(400);
|
||||
});
|
||||
|
||||
it.each(['encryptionKey', 'hmacKey', 'iv', 'expectedSourceLength'])('rejects bad base64 encoded %s', async (badprop: string) => {
|
||||
const request: Record<string, unknown> = validRequest();
|
||||
request[badprop] = 'aa&bb';
|
||||
const body = JSON.stringify(request);
|
||||
const res = await worker.fetch('http://localhost/copy', {
|
||||
method: 'PUT',
|
||||
body: body,
|
||||
headers: { 'Content-Length': body.length.toString() }
|
||||
});
|
||||
expect(res.status, await res.text()).toBe(400);
|
||||
});
|
||||
|
||||
it('handles missing source object', async () => {
|
||||
const request: Record<string, unknown> = validRequest();
|
||||
request['source'] = 'DoesNotExist';
|
||||
const body = JSON.stringify(request);
|
||||
const res = await worker.fetch('http://localhost/copy', {
|
||||
method: 'PUT',
|
||||
body: body,
|
||||
headers: { 'Content-Length': body.length.toString() }
|
||||
});
|
||||
expect(res.status, await res.text()).toBe(404);
|
||||
});
|
||||
|
||||
it('rejects bad sourceLength', async () => {
|
||||
await r2Put('attachments', 'abc', plaintext);
|
||||
const request: Record<string, unknown> = validRequest();
|
||||
request['expectedSourceLength'] = plaintext.length - 1;
|
||||
const body = JSON.stringify(request);
|
||||
const res = await worker.fetch('http://localhost/copy', {
|
||||
method: 'PUT',
|
||||
body: body,
|
||||
headers: { 'Content-Length': body.length.toString() }
|
||||
});
|
||||
expect(res.status, await res.text()).toBe(409);
|
||||
});
|
||||
|
||||
it.each([
|
||||
0, 63, 64, 1024 * 4 - 1, 1024, 1024 * 4 + 1, 1024 * 1024, 1024 * 1024 * 3 + 1
|
||||
])('copies %s bytes to backup bucket', async (plaintextLength: number) => {
|
||||
const plaintext = randomishBytes(plaintextLength);
|
||||
await r2Put('attachments', 'abc', plaintext);
|
||||
const body = JSON.stringify(validRequest(plaintext));
|
||||
const res = await worker.fetch('http://localhost/copy', {
|
||||
method: 'PUT',
|
||||
body: body,
|
||||
headers: { 'Content-Length': body.length.toString() }
|
||||
});
|
||||
expect(res.status, await res.text()).toBe(204);
|
||||
const payload = await r2Get('backups', 'my/abc');
|
||||
const decrypted = await webcryptoAuthenticateAndDecrypt(iv, key, hmacKey, payload!);
|
||||
expect(decrypted).toEqual(plaintext);
|
||||
});
|
||||
});
|
||||
200
workers/src/index.ts
Normal file
200
workers/src/index.ts
Normal file
@ -0,0 +1,200 @@
|
||||
// Copyright 2024 Signal Messenger, LLC
|
||||
// SPDX-License-Identifier: AGPL-3.0-only
|
||||
|
||||
import { error, IRequest, json, Router, StatusError } from 'itty-router';
|
||||
import { Encrypter, streamEncrypt } from './encrypt';
|
||||
|
||||
export interface Env {
|
||||
ATTACHMENT_BUCKET: R2Bucket;
|
||||
BACKUP_BUCKET: R2Bucket;
|
||||
}
|
||||
|
||||
const router = Router();
|
||||
router
|
||||
.put('/copy', copyHandler)
|
||||
.get('/usage', usageHandler)
|
||||
.get('/:bucketId', listHandler)
|
||||
.delete('/:bucketId/:id+', deletionHandler)
|
||||
.all('*', () => error(404));
|
||||
|
||||
|
||||
export default {
|
||||
async fetch(request: Request, env: Env, ctx: ExecutionContext): Promise<Response> {
|
||||
return await router.handle(request, env, ctx).catch(e => {
|
||||
console.log('error: ' + e.stack);
|
||||
return error(e);
|
||||
}).then(json);
|
||||
}
|
||||
};
|
||||
|
||||
async function deletionHandler(request: IRequest, env: Env): Promise<Response> {
|
||||
const bucket = getBucket(env, request.params.bucketId);
|
||||
if (bucket == null) {
|
||||
return error(404);
|
||||
}
|
||||
const head = await bucket.head(request.params.id);
|
||||
if (head == null) {
|
||||
return json({ bytesDeleted: 0 });
|
||||
}
|
||||
await bucket.delete(request.params.id);
|
||||
return json({ bytesDeleted: head.size });
|
||||
}
|
||||
|
||||
export interface ListResponse {
|
||||
cursor?: string,
|
||||
objects: {
|
||||
key: string,
|
||||
size: number
|
||||
}[]
|
||||
}
|
||||
|
||||
async function listHandler(request: IRequest, env: Env): Promise<Response> {
|
||||
const bucket = getBucket(env, request.params.bucketId);
|
||||
if (bucket == null) {
|
||||
return error(404);
|
||||
}
|
||||
if (Array.isArray(request.query['cursor'])) {
|
||||
return error(400, 'only one cursor parameter can be provided');
|
||||
}
|
||||
if (Array.isArray(request.query['limit'])) {
|
||||
return error(400, 'only one limit parameter can be provided');
|
||||
}
|
||||
if (Array.isArray(request.query['prefix'])) {
|
||||
return error(400, 'only one prefix parameter can be provided');
|
||||
}
|
||||
const limit = request.query['limit'] == null ? undefined : parseInt(request.query['limit']);
|
||||
if (limit != null && isNaN(limit)) {
|
||||
throw new StatusError(400, 'limit must be a number');
|
||||
}
|
||||
const response = await bucket.list({
|
||||
prefix: request.query['prefix'],
|
||||
cursor: request.query['cursor'],
|
||||
limit
|
||||
});
|
||||
const objects = response.objects.map(({ key, size }) => ({
|
||||
key: key,
|
||||
size: size
|
||||
}));
|
||||
const listResponse: ListResponse = {
|
||||
cursor: response.truncated ? response.cursor : undefined,
|
||||
objects
|
||||
};
|
||||
return json(listResponse);
|
||||
}
|
||||
|
||||
async function usageHandler(request: IRequest, env: Env): Promise<Response> {
|
||||
const bucket = env.BACKUP_BUCKET;
|
||||
const prefix = request.query['prefix'];
|
||||
if (prefix == null || Array.isArray(prefix) || prefix.length === 0) {
|
||||
return error(400, 'exactly one prefix parameter must be provided');
|
||||
}
|
||||
|
||||
if (Array.isArray(request.query['limit'])) {
|
||||
return error(400, 'only one limit parameter can be provided');
|
||||
}
|
||||
const limit = request.query['limit'] == null ? undefined : parseInt(request.query['limit']);
|
||||
if (limit != null && isNaN(limit)) {
|
||||
throw new StatusError(400, 'limit must be a number');
|
||||
}
|
||||
|
||||
|
||||
let totalObjects = 0;
|
||||
let totalBytes = 0;
|
||||
let cursor: undefined | string = undefined;
|
||||
do {
|
||||
const response = await bucket.list({ prefix, limit, cursor });
|
||||
totalBytes = response.objects.reduce((acc, obj) => acc + obj.size, totalBytes);
|
||||
totalObjects += response.objects.length;
|
||||
cursor = response.truncated ? response.cursor : undefined;
|
||||
} while (cursor != null);
|
||||
return json({ bytesUsed: totalBytes, numObjects: totalObjects });
|
||||
}
|
||||
|
||||
interface CopyRequest {
|
||||
encryptionKey: string,
|
||||
hmacKey: string,
|
||||
iv: string,
|
||||
source: string,
|
||||
expectedSourceLength: number,
|
||||
dst: string
|
||||
}
|
||||
|
||||
function isCopyRequest(o: unknown): o is CopyRequest {
|
||||
return o != null
|
||||
&& typeof o === 'object'
|
||||
&& 'encryptionKey' in o && typeof (o.encryptionKey) === 'string'
|
||||
&& 'hmacKey' in o && typeof (o.hmacKey) === 'string'
|
||||
&& 'iv' in o && typeof (o.iv) === 'string'
|
||||
&& 'source' in o && typeof (o.source) === 'string'
|
||||
&& 'expectedSourceLength' in o && typeof (o.expectedSourceLength) === 'number'
|
||||
&& 'dst' in o && typeof (o.dst) === 'string';
|
||||
}
|
||||
|
||||
async function copyHandler(request: IRequest, env: Env): Promise<Response> {
|
||||
const copyRequest = await request.json();
|
||||
if (!isCopyRequest(copyRequest)) {
|
||||
return error(400, 'invalid copy request');
|
||||
}
|
||||
|
||||
const aesKeyBuf = b64decode(copyRequest.encryptionKey);
|
||||
if (aesKeyBuf == null) {
|
||||
return error(400, 'invalid key, must be base64');
|
||||
}
|
||||
if (aesKeyBuf.length != 32) {
|
||||
return error(400, 'invalid key, must be length 32');
|
||||
}
|
||||
|
||||
const hmacKey = b64decode(copyRequest.hmacKey);
|
||||
if (hmacKey == null) {
|
||||
return error(400, 'invalid hmac key, must be base64');
|
||||
}
|
||||
if (hmacKey.length != 32) {
|
||||
return error(400, 'invalid hmac key, must be length 32');
|
||||
}
|
||||
|
||||
const iv = b64decode(copyRequest.iv);
|
||||
if (iv == null) {
|
||||
return error(400, 'invalid iv, must be base64');
|
||||
}
|
||||
if (iv.length != 16) {
|
||||
return error(400, 'invalid iv, must be length 16');
|
||||
}
|
||||
|
||||
const r2Source = await env.ATTACHMENT_BUCKET.get(copyRequest.source);
|
||||
if (r2Source === null) {
|
||||
return error(404, 'source object not found');
|
||||
}
|
||||
|
||||
if (r2Source.size !== copyRequest.expectedSourceLength) {
|
||||
return error(409, `request expectedSourceLength ${copyRequest.expectedSourceLength} did not match actual sourceLength ${r2Source.size}`);
|
||||
}
|
||||
|
||||
const encrypter = await Encrypter.create(iv, hmacKey, aesKeyBuf);
|
||||
const { readable, writable } = new FixedLengthStream(encrypter.encryptedLength(r2Source.size));
|
||||
const putRequest = env.BACKUP_BUCKET.put(copyRequest.dst, readable, {
|
||||
httpMetadata: r2Source.httpMetadata
|
||||
});
|
||||
await streamEncrypt(encrypter, r2Source.body, writable);
|
||||
await putRequest;
|
||||
return new Response(null, { status: 204 });
|
||||
}
|
||||
|
||||
|
||||
function getBucket(env: Env, bucketId: string): R2Bucket | undefined {
|
||||
switch (bucketId) {
|
||||
case 'attachments':
|
||||
return env.ATTACHMENT_BUCKET;
|
||||
case 'backups':
|
||||
return env.BACKUP_BUCKET;
|
||||
default:
|
||||
return undefined;
|
||||
}
|
||||
}
|
||||
|
||||
function b64decode(b64: string): Uint8Array | null {
|
||||
try {
|
||||
return Uint8Array.from(atob(b64), c => c.charCodeAt(0));
|
||||
} catch (e) {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
74
workers/src/r2TestWorker.ts
Normal file
74
workers/src/r2TestWorker.ts
Normal file
@ -0,0 +1,74 @@
|
||||
// Copyright 2024 Signal Messenger, LLC
|
||||
// SPDX-License-Identifier: AGPL-3.0-only
|
||||
|
||||
import { error, json, Router } from 'itty-router';
|
||||
|
||||
export interface Env {
|
||||
ATTACHMENT_BUCKET: R2Bucket;
|
||||
BACKUP_BUCKET: R2Bucket;
|
||||
}
|
||||
|
||||
const router = Router();
|
||||
router.get('/:bucketId/:id+', async (request, env) => {
|
||||
const bucket = getBucket(env, request.params.bucketId);
|
||||
if (bucket == null) {
|
||||
return error(404);
|
||||
}
|
||||
const object = await bucket.get(request.params.id);
|
||||
if (object == null) {
|
||||
return error(404);
|
||||
}
|
||||
return new Response(object.body, { status: 200 });
|
||||
});
|
||||
router.put('/:bucketId/:id+', async (request, env) => {
|
||||
const bucket = getBucket(env, request.params.bucketId);
|
||||
if (bucket == null) {
|
||||
return error(404);
|
||||
}
|
||||
if (request.body == null) {
|
||||
return error(400);
|
||||
}
|
||||
await bucket.put(request.params.id, request.body as ReadableStream<never>, { httpMetadata: request.headers });
|
||||
return new Response(null, { status: 200 });
|
||||
});
|
||||
|
||||
router.delete('/:bucketId', async (request, env) => {
|
||||
const bucket = getBucket(env, request.params.bucketId);
|
||||
if (bucket == null) {
|
||||
return error(404);
|
||||
}
|
||||
|
||||
let cursor: undefined | string = undefined;
|
||||
do {
|
||||
const response = await bucket.list({ cursor });
|
||||
await bucket.delete(response.objects.map(obj => obj.key));
|
||||
if (response.truncated) {
|
||||
cursor = response.cursor;
|
||||
}
|
||||
} while (cursor != null);
|
||||
return new Response(null, { status: 200 });
|
||||
});
|
||||
|
||||
router.all('*', () => error(404));
|
||||
|
||||
|
||||
export default {
|
||||
async fetch(request: Request, env: Env, ctx: ExecutionContext): Promise<Response> {
|
||||
return await router.handle(request, env, ctx).catch(e => {
|
||||
console.log('error: ' + e.stack);
|
||||
return error(e);
|
||||
}).then(json);
|
||||
}
|
||||
};
|
||||
|
||||
|
||||
function getBucket(env: Env, bucketId: string): R2Bucket | undefined {
|
||||
switch (bucketId) {
|
||||
case 'attachments':
|
||||
return env.ATTACHMENT_BUCKET;
|
||||
case 'backups':
|
||||
return env.BACKUP_BUCKET;
|
||||
default:
|
||||
return undefined;
|
||||
}
|
||||
}
|
||||
86
workers/src/testutil.ts
Normal file
86
workers/src/testutil.ts
Normal file
@ -0,0 +1,86 @@
|
||||
// Copyright 2024 Signal Messenger, LLC
|
||||
// SPDX-License-Identifier: AGPL-3.0-only
|
||||
|
||||
import crypto from 'crypto';
|
||||
import { expect } from 'vitest';
|
||||
|
||||
export function randBytes(n: number): Uint8Array {
|
||||
const arr = new Uint8Array(n);
|
||||
crypto.getRandomValues(arr);
|
||||
return arr;
|
||||
}
|
||||
|
||||
/**
|
||||
* Generate large random looking data to use when validating encryption algorithms. This can be faster that actual
|
||||
* random data for large buffers if there isn't enough available entropy on the system.
|
||||
*/
|
||||
export function randomishBytes(n: number): Uint8Array {
|
||||
const curr = new Uint8Array(32);
|
||||
const arr = new Uint8Array(n);
|
||||
for (let offset = 0; offset < n; offset += 32) {
|
||||
const hasher = crypto.createHash('sha256');
|
||||
hasher.update(curr);
|
||||
curr.set(hasher.digest());
|
||||
arr.set(curr);
|
||||
}
|
||||
return arr;
|
||||
}
|
||||
|
||||
export function readableStreamFrom(bytes: Uint8Array): ReadableStream<Uint8Array> {
|
||||
return new ReadableStream<Uint8Array>({
|
||||
start(controller) {
|
||||
controller.enqueue(bytes);
|
||||
controller.close();
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
export async function readAll(stream: ReadableStream<Uint8Array>): Promise<Uint8Array> {
|
||||
const chunks: Uint8Array[] = [];
|
||||
for await (const chunk of stream) {
|
||||
// save a copy of the chunk
|
||||
chunks.push(new Uint8Array(chunk));
|
||||
}
|
||||
return concat(chunks);
|
||||
}
|
||||
|
||||
export function concat(data: Uint8Array[]): Uint8Array {
|
||||
const size = data.reduce((len, nxt) => len + nxt.length, 0);
|
||||
const ret = new Uint8Array(size);
|
||||
let offset = 0;
|
||||
for (const arr of data) {
|
||||
ret.set(arr, offset);
|
||||
offset += arr.length;
|
||||
}
|
||||
return ret;
|
||||
}
|
||||
|
||||
export async function webcryptoHmacVerify(hmac: Uint8Array, key: Uint8Array, ...data: Uint8Array[]): Promise<boolean> {
|
||||
return await crypto.webcrypto.subtle.verify({
|
||||
name: 'hmac',
|
||||
hash: 'SHA-256'
|
||||
},
|
||||
await crypto.webcrypto.subtle.importKey('raw', key, {
|
||||
name: 'hmac',
|
||||
hash: 'SHA-256'
|
||||
}, false, ['verify']),
|
||||
hmac,
|
||||
concat(data));
|
||||
}
|
||||
|
||||
|
||||
export async function aesKey(keyBytes: Uint8Array): Promise<crypto.webcrypto.CryptoKey> {
|
||||
return await crypto.subtle.importKey('raw', keyBytes, 'AES-CBC', false, ['encrypt', 'decrypt']);
|
||||
}
|
||||
|
||||
export async function webcryptoDecrypt(iv: Uint8Array, key: Uint8Array, data: Uint8Array): Promise<Uint8Array> {
|
||||
return new Uint8Array(await crypto.subtle.decrypt({ name: 'AES-CBC', iv }, await aesKey(key), data));
|
||||
}
|
||||
|
||||
export async function webcryptoAuthenticateAndDecrypt(iv: Uint8Array, key: Uint8Array, hmacKey: Uint8Array, ciphertext: Uint8Array): Promise<Uint8Array> {
|
||||
expect(ciphertext.subarray(0, 16)).toEqual(iv);
|
||||
const encrypted = ciphertext!.subarray(16, ciphertext.length - 32);
|
||||
const hmac = ciphertext.subarray(ciphertext.length - 32, ciphertext.length);
|
||||
expect(await webcryptoHmacVerify(hmac, hmacKey, ciphertext.subarray(0, ciphertext.length - 32))).toBe(true);
|
||||
return await webcryptoDecrypt(iv, key, encrypted);
|
||||
}
|
||||
120
workers/tsconfig.json
Normal file
120
workers/tsconfig.json
Normal file
@ -0,0 +1,120 @@
|
||||
{
|
||||
"compilerOptions": {
|
||||
/* Visit https://aka.ms/tsconfig.json to read more about this file */
|
||||
|
||||
/* Projects */
|
||||
// "incremental": true, /* Enable incremental compilation */
|
||||
// "composite": true, /* Enable constraints that allow a TypeScript project to be used with project references. */
|
||||
// "tsBuildInfoFile": "./", /* Specify the folder for .tsbuildinfo incremental compilation files. */
|
||||
// "disableSourceOfProjectReferenceRedirect": true, /* Disable preferring source files instead of declaration files when referencing composite projects */
|
||||
// "disableSolutionSearching": true, /* Opt a project out of multi-project reference checking when editing. */
|
||||
// "disableReferencedProjectLoad": true, /* Reduce the number of projects loaded automatically by TypeScript. */
|
||||
|
||||
/* Language and Environment */
|
||||
"target": "es2021"
|
||||
/* Set the JavaScript language version for emitted JavaScript and include compatible library declarations. */,
|
||||
"lib": [
|
||||
"es2021"
|
||||
]
|
||||
/* Specify a set of bundled library declaration files that describe the target runtime environment. */,
|
||||
"jsx": "react"
|
||||
/* Specify what JSX code is generated. */,
|
||||
// "experimentalDecorators": true, /* Enable experimental support for TC39 stage 2 draft decorators. */
|
||||
// "emitDecoratorMetadata": true, /* Emit design-type metadata for decorated declarations in source files. */
|
||||
// "jsxFactory": "", /* Specify the JSX factory function used when targeting React JSX emit, e.g. 'React.createElement' or 'h' */
|
||||
// "jsxFragmentFactory": "", /* Specify the JSX Fragment reference used for fragments when targeting React JSX emit e.g. 'React.Fragment' or 'Fragment'. */
|
||||
// "jsxImportSource": "", /* Specify module specifier used to import the JSX factory functions when using `jsx: react-jsx*`.` */
|
||||
// "reactNamespace": "", /* Specify the object invoked for `createElement`. This only applies when targeting `react` JSX emit. */
|
||||
// "noLib": true, /* Disable including any library files, including the default lib.d.ts. */
|
||||
// "useDefineForClassFields": true, /* Emit ECMAScript-standard-compliant class fields. */
|
||||
|
||||
/* Modules */
|
||||
"module": "es2022"
|
||||
/* Specify what module code is generated. */,
|
||||
// "rootDir": "./", /* Specify the root folder within your source files. */
|
||||
"moduleResolution": "node"
|
||||
/* Specify how TypeScript looks up a file from a given module specifier. */,
|
||||
// "baseUrl": "./", /* Specify the base directory to resolve non-relative module names. */
|
||||
// "paths": {}, /* Specify a set of entries that re-map imports to additional lookup locations. */
|
||||
// "rootDirs": [], /* Allow multiple folders to be treated as one when resolving modules. */
|
||||
// "typeRoots": [], /* Specify multiple folders that act like `./node_modules/@types`. */
|
||||
"types": [
|
||||
"@cloudflare/workers-types",
|
||||
"vitest-environment-miniflare/globals"
|
||||
]
|
||||
/* Specify type package names to be included without being referenced in a source file. */,
|
||||
// "allowUmdGlobalAccess": true, /* Allow accessing UMD globals from modules. */
|
||||
"resolveJsonModule": true
|
||||
/* Enable importing .json files */,
|
||||
// "noResolve": true, /* Disallow `import`s, `require`s or `<reference>`s from expanding the number of files TypeScript should add to a project. */
|
||||
|
||||
/* JavaScript Support */
|
||||
"allowJs": true
|
||||
/* Allow JavaScript files to be a part of your program. Use the `checkJS` option to get errors from these files. */,
|
||||
"checkJs": false
|
||||
/* Enable error reporting in type-checked JavaScript files. */,
|
||||
// "maxNodeModuleJsDepth": 1, /* Specify the maximum folder depth used for checking JavaScript files from `node_modules`. Only applicable with `allowJs`. */
|
||||
|
||||
/* Emit */
|
||||
// "declaration": true, /* Generate .d.ts files from TypeScript and JavaScript files in your project. */
|
||||
// "declarationMap": true, /* Create sourcemaps for d.ts files. */
|
||||
// "emitDeclarationOnly": true, /* Only output d.ts files and not JavaScript files. */
|
||||
// "sourceMap": true, /* Create source map files for emitted JavaScript files. */
|
||||
// "outFile": "./", /* Specify a file that bundles all outputs into one JavaScript file. If `declaration` is true, also designates a file that bundles all .d.ts output. */
|
||||
// "outDir": "./", /* Specify an output folder for all emitted files. */
|
||||
// "removeComments": true, /* Disable emitting comments. */
|
||||
"noEmit": true
|
||||
/* Disable emitting files from a compilation. */,
|
||||
// "importHelpers": true, /* Allow importing helper functions from tslib once per project, instead of including them per-file. */
|
||||
// "importsNotUsedAsValues": "remove", /* Specify emit/checking behavior for imports that are only used for types */
|
||||
// "downlevelIteration": true, /* Emit more compliant, but verbose and less performant JavaScript for iteration. */
|
||||
// "sourceRoot": "", /* Specify the root path for debuggers to find the reference source code. */
|
||||
// "mapRoot": "", /* Specify the location where debugger should locate map files instead of generated locations. */
|
||||
// "inlineSourceMap": true, /* Include sourcemap files inside the emitted JavaScript. */
|
||||
// "inlineSources": true, /* Include source code in the sourcemaps inside the emitted JavaScript. */
|
||||
// "emitBOM": true, /* Emit a UTF-8 Byte Order Mark (BOM) in the beginning of output files. */
|
||||
// "newLine": "crlf", /* Set the newline character for emitting files. */
|
||||
// "stripInternal": true, /* Disable emitting declarations that have `@internal` in their JSDoc comments. */
|
||||
// "noEmitHelpers": true, /* Disable generating custom helper functions like `__extends` in compiled output. */
|
||||
// "noEmitOnError": true, /* Disable emitting files if any type checking errors are reported. */
|
||||
// "preserveConstEnums": true, /* Disable erasing `const enum` declarations in generated code. */
|
||||
// "declarationDir": "./", /* Specify the output directory for generated declaration files. */
|
||||
// "preserveValueImports": true, /* Preserve unused imported values in the JavaScript output that would otherwise be removed. */
|
||||
|
||||
/* Interop Constraints */
|
||||
"isolatedModules": true
|
||||
/* Ensure that each file can be safely transpiled without relying on other imports. */,
|
||||
"allowSyntheticDefaultImports": true
|
||||
/* Allow 'import x from y' when a module doesn't have a default export. */,
|
||||
// "esModuleInterop": true /* Emit additional JavaScript to ease support for importing CommonJS modules. This enables `allowSyntheticDefaultImports` for type compatibility. */,
|
||||
// "preserveSymlinks": true, /* Disable resolving symlinks to their realpath. This correlates to the same flag in node. */
|
||||
"forceConsistentCasingInFileNames": true
|
||||
/* Ensure that casing is correct in imports. */,
|
||||
/* Type Checking */
|
||||
"strict": true
|
||||
/* Enable all strict type-checking options. */,
|
||||
// "noImplicitAny": true, /* Enable error reporting for expressions and declarations with an implied `any` type.. */
|
||||
// "strictNullChecks": true, /* When type checking, take into account `null` and `undefined`. */
|
||||
// "strictFunctionTypes": true, /* When assigning functions, check to ensure parameters and the return values are subtype-compatible. */
|
||||
// "strictBindCallApply": true, /* Check that the arguments for `bind`, `call`, and `apply` methods match the original function. */
|
||||
// "strictPropertyInitialization": true, /* Check for class properties that are declared but not set in the constructor. */
|
||||
// "noImplicitThis": true, /* Enable error reporting when `this` is given the type `any`. */
|
||||
// "useUnknownInCatchVariables": true, /* Type catch clause variables as 'unknown' instead of 'any'. */
|
||||
// "alwaysStrict": true, /* Ensure 'use strict' is always emitted. */
|
||||
// "noUnusedLocals": true, /* Enable error reporting when a local variables aren't read. */
|
||||
// "noUnusedParameters": true, /* Raise an error when a function parameter isn't read */
|
||||
// "exactOptionalPropertyTypes": true, /* Interpret optional property types as written, rather than adding 'undefined'. */
|
||||
// "noImplicitReturns": true, /* Enable error reporting for codepaths that do not explicitly return in a function. */
|
||||
// "noFallthroughCasesInSwitch": true, /* Enable error reporting for fallthrough cases in switch statements. */
|
||||
// "noUncheckedIndexedAccess": true, /* Include 'undefined' in index signature results */
|
||||
// "noImplicitOverride": true, /* Ensure overriding members in derived classes are marked with an override modifier. */
|
||||
// "noPropertyAccessFromIndexSignature": true, /* Enforces using indexed accessors for keys declared using an indexed type */
|
||||
// "allowUnusedLabels": true, /* Disable error reporting for unused labels. */
|
||||
// "allowUnreachableCode": true, /* Disable error reporting for unreachable code. */
|
||||
|
||||
/* Completeness */
|
||||
// "skipDefaultLibCheck": true, /* Skip type checking .d.ts files that are included with TypeScript. */
|
||||
"skipLibCheck": true
|
||||
/* Skip type checking all .d.ts files. */
|
||||
}
|
||||
}
|
||||
31
workers/wrangler.toml
Normal file
31
workers/wrangler.toml
Normal file
@ -0,0 +1,31 @@
|
||||
# Copyright 2024 Signal Messenger, LLC
|
||||
# SPDX-License-Identifier: AGPL-3.0-only
|
||||
|
||||
name = "storage-manager-dev"
|
||||
main = "src/index.ts"
|
||||
logpush = true
|
||||
compatibility_date = "2023-10-30"
|
||||
workers_dev = false
|
||||
|
||||
# required since we use node crypto's streaming HMAC
|
||||
compatibility_flags = ["nodejs_compat"]
|
||||
|
||||
# Specifies the r2 buckets. r2 bucket names are scoped to your account (not global). The buckets should be publicly inaccessible.
|
||||
r2_buckets = [
|
||||
{ binding = "ATTACHMENT_BUCKET", bucket_name = "attachments-staging", preview_bucket_name = "attachments-staging" },
|
||||
{ binding = "BACKUP_BUCKET", bucket_name = "backups-staging", preview_bucket_name = "backups-staging" }
|
||||
]
|
||||
|
||||
[env.production]
|
||||
name = "storage-manager"
|
||||
r2_buckets = [
|
||||
{ binding = "ATTACHMENT_BUCKET", bucket_name = "attachments", preview_bucket_name = "attachments" },
|
||||
{ binding = "BACKUP_BUCKET", bucket_name = "backups", preview_bucket_name = "backups" }
|
||||
]
|
||||
|
||||
[env.staging]
|
||||
name = "storage-manager-staging"
|
||||
r2_buckets = [
|
||||
{ binding = "ATTACHMENT_BUCKET", bucket_name = "attachments-staging", preview_bucket_name = "attachments-staging" },
|
||||
{ binding = "BACKUP_BUCKET", bucket_name = "backups-staging", preview_bucket_name = "backups-staging" }
|
||||
]
|
||||
Loading…
Reference in New Issue
Block a user