1 /*
2 * Copyright (C) 2009-2010, Google Inc.
3 * and other copyright owners as documented in the project's IP log.
4 *
5 * This program and the accompanying materials are made available
6 * under the terms of the Eclipse Distribution License v1.0 which
7 * accompanies this distribution, is reproduced below, and is
8 * available at http://www.eclipse.org/org/documents/edl-v10.php
9 *
10 * All rights reserved.
11 *
12 * Redistribution and use in source and binary forms, with or
13 * without modification, are permitted provided that the following
14 * conditions are met:
15 *
16 * - Redistributions of source code must retain the above copyright
17 * notice, this list of conditions and the following disclaimer.
18 *
19 * - Redistributions in binary form must reproduce the above
20 * copyright notice, this list of conditions and the following
21 * disclaimer in the documentation and/or other materials provided
22 * with the distribution.
23 *
24 * - Neither the name of the Eclipse Foundation, Inc. nor the
25 * names of its contributors may be used to endorse or promote
26 * products derived from this software without specific prior
27 * written permission.
28 *
29 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND
30 * CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES,
31 * INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
32 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
33 * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR
34 * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
35 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
36 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
37 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
38 * CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
39 * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
40 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
41 * ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
42 */
43
44 package org.eclipse.jgit.http.server.resolver;
45
46 import javax.servlet.http.HttpServletRequest;
47
48 import org.eclipse.jgit.http.server.GitServlet;
49 import org.eclipse.jgit.lib.Config;
50 import org.eclipse.jgit.lib.Repository;
51 import org.eclipse.jgit.lib.Config.SectionParser;
52 import org.eclipse.jgit.transport.resolver.ServiceNotAuthorizedException;
53 import org.eclipse.jgit.transport.resolver.ServiceNotEnabledException;
54
55 /**
56 * Controls access to bare files in a repository.
57 * <p>
58 * Older HTTP clients which do not speak the smart HTTP variant of the Git
59 * protocol fetch from a repository by directly getting its objects and pack
60 * files. This class, along with the {@code http.getanyfile} per-repository
61 * configuration setting, can be used by {@link GitServlet} to control whether
62 * or not these older clients are permitted to read these direct files.
63 */
64 public class AsIsFileService {
65 /** Always throws {@link ServiceNotEnabledException}. */
66 public static final AsIsFileService DISABLED = new AsIsFileService() {
67 @Override
68 public void access(HttpServletRequest req, Repository db)
69 throws ServiceNotEnabledException {
70 throw new ServiceNotEnabledException();
71 }
72 };
73
74 private static final SectionParser<ServiceConfig> CONFIG = new SectionParser<ServiceConfig>() {
75 public ServiceConfig parse(final Config cfg) {
76 return new ServiceConfig(cfg);
77 }
78 };
79
80 private static class ServiceConfig {
81 final boolean enabled;
82
83 ServiceConfig(final Config cfg) {
84 enabled = cfg.getBoolean("http", "getanyfile", true);
85 }
86 }
87
88 /**
89 * Determine if {@code http.getanyfile} is enabled in the configuration.
90 *
91 * @param db
92 * the repository to check.
93 * @return {@code false} if {@code http.getanyfile} was explicitly set to
94 * {@code false} in the repository's configuration file; otherwise
95 * {@code true}.
96 */
97 protected static boolean isEnabled(Repository db) {
98 return db.getConfig().get(CONFIG).enabled;
99 }
100
101 /**
102 * Determine if access to any bare file of the repository is allowed.
103 * <p>
104 * This method silently succeeds if the request is allowed, or fails by
105 * throwing a checked exception if access should be denied.
106 * <p>
107 * The default implementation of this method checks {@code http.getanyfile},
108 * throwing {@link ServiceNotEnabledException} if it was explicitly set to
109 * {@code false}, and otherwise succeeding silently.
110 *
111 * @param req
112 * current HTTP request, in case information from the request may
113 * help determine the access request.
114 * @param db
115 * the repository the request would obtain a bare file from.
116 * @throws ServiceNotEnabledException
117 * bare file access is not allowed on the target repository, by
118 * any user, for any reason.
119 * @throws ServiceNotAuthorizedException
120 * bare file access is not allowed for this HTTP request and
121 * repository, such as due to a permission error.
122 */
123 public void access(HttpServletRequest req, Repository db)
124 throws ServiceNotEnabledException, ServiceNotAuthorizedException {
125 if (!isEnabled(db))
126 throw new ServiceNotEnabledException();
127 }
128 }