Lindenii Project Forge
templates shall no longer be a global variable
// SPDX-License-Identifier: AGPL-3.0-only // SPDX-FileCopyrightText: Copyright (c) 2025 Runxi Yu <https://runxiyu.org> package forge import ( "net/http" "strings" "github.com/go-git/go-git/v5" "github.com/go-git/go-git/v5/plumbing" "github.com/go-git/go-git/v5/plumbing/storer" "go.lindenii.runxiyu.org/forge/internal/misc" ) // httpHandleRepoBranches provides the branches page in repos. func (s *Server) httpHandleRepoBranches(writer http.ResponseWriter, _ *http.Request, params map[string]any) { var repo *git.Repository var repoName string var groupPath []string var err error var notes []string var branches []string var branchesIter storer.ReferenceIter repo, repoName, groupPath = params["repo"].(*git.Repository), params["repo_name"].(string), params["group_path"].([]string) if strings.Contains(repoName, "\n") || misc.SliceContainsNewlines(groupPath) { notes = append(notes, "Path contains newlines; HTTP Git access impossible") } branchesIter, err = repo.Branches() if err == nil { _ = branchesIter.ForEach(func(branch *plumbing.Reference) error { branches = append(branches, branch.Name().Short()) return nil }) } params["branches"] = branches params["http_clone_url"] = s.genHTTPRemoteURL(groupPath, repoName) params["ssh_clone_url"] = s.genSSHRemoteURL(groupPath, repoName) params["notes"] = notes
renderTemplate(writer, "repo_branches", params)
s.renderTemplate(writer, "repo_branches", params)
}
// SPDX-License-Identifier: AGPL-3.0-only // SPDX-FileCopyrightText: Copyright (c) 2025 Runxi Yu <https://runxiyu.org> package forge import ( "errors" "net/http" "path/filepath" "strconv" "github.com/jackc/pgx/v5" "github.com/jackc/pgx/v5/pgtype" "go.lindenii.runxiyu.org/forge/internal/misc" "go.lindenii.runxiyu.org/forge/internal/web" ) // httpHandleGroupIndex provides index pages for groups, which includes a list // of its subgroups and repos, as well as a form for group maintainers to // create repos. func (s *Server) httpHandleGroupIndex(writer http.ResponseWriter, request *http.Request, params map[string]any) { var groupPath []string var repos []nameDesc var subgroups []nameDesc var err error var groupID int var groupDesc string groupPath = params["group_path"].([]string) // The group itself err = s.database.QueryRow(request.Context(), ` WITH RECURSIVE group_path_cte AS ( SELECT id, parent_group, name, 1 AS depth FROM groups WHERE name = ($1::text[])[1] AND parent_group IS NULL UNION ALL SELECT g.id, g.parent_group, g.name, group_path_cte.depth + 1 FROM groups g JOIN group_path_cte ON g.parent_group = group_path_cte.id WHERE g.name = ($1::text[])[group_path_cte.depth + 1] AND group_path_cte.depth + 1 <= cardinality($1::text[]) ) SELECT c.id, COALESCE(g.description, '') FROM group_path_cte c JOIN groups g ON g.id = c.id WHERE c.depth = cardinality($1::text[]) `, pgtype.FlatArray[string](groupPath), ).Scan(&groupID, &groupDesc) if errors.Is(err, pgx.ErrNoRows) {
web.ErrorPage404(templates, writer, params)
web.ErrorPage404(s.templates, writer, params)
return } else if err != nil {
web.ErrorPage500(templates, writer, params, "Error getting group: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error getting group: "+err.Error())
return } // ACL var count int err = s.database.QueryRow(request.Context(), ` SELECT COUNT(*) FROM user_group_roles WHERE user_id = $1 AND group_id = $2 `, params["user_id"].(int), groupID).Scan(&count) if err != nil {
web.ErrorPage500(templates, writer, params, "Error checking access: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error checking access: "+err.Error())
return } directAccess := (count > 0) if request.Method == http.MethodPost { if !directAccess {
web.ErrorPage403(templates, writer, params, "You do not have direct access to this group")
web.ErrorPage403(s.templates, writer, params, "You do not have direct access to this group")
return } repoName := request.FormValue("repo_name") repoDesc := request.FormValue("repo_desc") contribReq := request.FormValue("repo_contrib") if repoName == "" {
web.ErrorPage400(templates, writer, params, "Repo name is required")
web.ErrorPage400(s.templates, writer, params, "Repo name is required")
return } var newRepoID int err := s.database.QueryRow( request.Context(), `INSERT INTO repos (name, description, group_id, contrib_requirements) VALUES ($1, $2, $3, $4) RETURNING id`, repoName, repoDesc, groupID, contribReq, ).Scan(&newRepoID) if err != nil {
web.ErrorPage500(templates, writer, params, "Error creating repo: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error creating repo: "+err.Error())
return } filePath := filepath.Join(s.config.Git.RepoDir, strconv.Itoa(newRepoID)+".git") _, err = s.database.Exec( request.Context(), `UPDATE repos SET filesystem_path = $1 WHERE id = $2`, filePath, newRepoID, ) if err != nil {
web.ErrorPage500(templates, writer, params, "Error updating repo path: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error updating repo path: "+err.Error())
return } if err = s.gitInit(filePath); err != nil {
web.ErrorPage500(templates, writer, params, "Error initializing repo: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error initializing repo: "+err.Error())
return } misc.RedirectUnconditionally(writer, request) return } // Repos var rows pgx.Rows rows, err = s.database.Query(request.Context(), ` SELECT name, COALESCE(description, '') FROM repos WHERE group_id = $1 `, groupID) if err != nil {
web.ErrorPage500(templates, writer, params, "Error getting repos: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error getting repos: "+err.Error())
return } defer rows.Close() for rows.Next() { var name, description string if err = rows.Scan(&name, &description); err != nil {
web.ErrorPage500(templates, writer, params, "Error getting repos: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error getting repos: "+err.Error())
return } repos = append(repos, nameDesc{name, description}) } if err = rows.Err(); err != nil {
web.ErrorPage500(templates, writer, params, "Error getting repos: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error getting repos: "+err.Error())
return } // Subgroups rows, err = s.database.Query(request.Context(), ` SELECT name, COALESCE(description, '') FROM groups WHERE parent_group = $1 `, groupID) if err != nil {
web.ErrorPage500(templates, writer, params, "Error getting subgroups: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error getting subgroups: "+err.Error())
return } defer rows.Close() for rows.Next() { var name, description string if err = rows.Scan(&name, &description); err != nil {
web.ErrorPage500(templates, writer, params, "Error getting subgroups: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error getting subgroups: "+err.Error())
return } subgroups = append(subgroups, nameDesc{name, description}) } if err = rows.Err(); err != nil {
web.ErrorPage500(templates, writer, params, "Error getting subgroups: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error getting subgroups: "+err.Error())
return } params["repos"] = repos params["subgroups"] = subgroups params["description"] = groupDesc params["direct_access"] = directAccess
renderTemplate(writer, "group", params)
s.renderTemplate(writer, "group", params)
}
// SPDX-License-Identifier: AGPL-3.0-only // SPDX-FileCopyrightText: Copyright (c) 2025 Runxi Yu <https://runxiyu.org> package forge import ( "net/http" "runtime" "github.com/dustin/go-humanize" "go.lindenii.runxiyu.org/forge/internal/web" ) // httpHandleIndex provides the main index page which includes a list of groups // and some global information such as SSH keys. func (s *Server) httpHandleIndex(writer http.ResponseWriter, request *http.Request, params map[string]any) { var err error var groups []nameDesc groups, err = s.queryNameDesc(request.Context(), "SELECT name, COALESCE(description, '') FROM groups WHERE parent_group IS NULL") if err != nil {
web.ErrorPage500(templates, writer, params, "Error querying groups: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error querying groups: "+err.Error())
return } params["groups"] = groups // Memory currently allocated memstats := runtime.MemStats{} //exhaustruct:ignore runtime.ReadMemStats(&memstats) params["mem"] = humanize.IBytes(memstats.Alloc)
renderTemplate(writer, "index", params)
s.renderTemplate(writer, "index", params)
}
// SPDX-License-Identifier: AGPL-3.0-only // SPDX-FileCopyrightText: Copyright (c) 2025 Runxi Yu <https://runxiyu.org> package forge import ( "crypto/rand" "encoding/base64" "errors" "fmt" "net/http" "time" "github.com/alexedwards/argon2id" "github.com/jackc/pgx/v5" "go.lindenii.runxiyu.org/forge/internal/web" ) // httpHandleLogin provides the login page for local users. func (s *Server) httpHandleLogin(writer http.ResponseWriter, request *http.Request, params map[string]any) { var username, password string var userID int var passwordHash string var err error var passwordMatches bool var cookieValue string var now time.Time var expiry time.Time var cookie http.Cookie if request.Method != http.MethodPost {
renderTemplate(writer, "login", params)
s.renderTemplate(writer, "login", params)
return } username = request.PostFormValue("username") password = request.PostFormValue("password") err = s.database.QueryRow(request.Context(), "SELECT id, COALESCE(password, '') FROM users WHERE username = $1", username, ).Scan(&userID, &passwordHash) if err != nil { if errors.Is(err, pgx.ErrNoRows) { params["login_error"] = "Unknown username"
renderTemplate(writer, "login", params)
s.renderTemplate(writer, "login", params)
return }
web.ErrorPage500(templates, writer, params, "Error querying user information: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error querying user information: "+err.Error())
return } if passwordHash == "" { params["login_error"] = "User has no password"
renderTemplate(writer, "login", params)
s.renderTemplate(writer, "login", params)
return } if passwordMatches, err = argon2id.ComparePasswordAndHash(password, passwordHash); err != nil {
web.ErrorPage500(templates, writer, params, "Error comparing password and hash: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error comparing password and hash: "+err.Error())
return } if !passwordMatches { params["login_error"] = "Invalid password"
renderTemplate(writer, "login", params)
s.renderTemplate(writer, "login", params)
return } if cookieValue, err = randomUrlsafeStr(16); err != nil {
web.ErrorPage500(templates, writer, params, "Error getting random string: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error getting random string: "+err.Error())
return } now = time.Now() expiry = now.Add(time.Duration(s.config.HTTP.CookieExpiry) * time.Second) cookie = http.Cookie{ Name: "session", Value: cookieValue, SameSite: http.SameSiteLaxMode, HttpOnly: true, Secure: false, // TODO Expires: expiry, Path: "/", } //exhaustruct:ignore http.SetCookie(writer, &cookie) _, err = s.database.Exec(request.Context(), "INSERT INTO sessions (user_id, session_id) VALUES ($1, $2)", userID, cookieValue) if err != nil {
web.ErrorPage500(templates, writer, params, "Error inserting session: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error inserting session: "+err.Error())
return } http.Redirect(writer, request, "/", http.StatusSeeOther) } // randomUrlsafeStr generates a random string of the given entropic size // using the URL-safe base64 encoding. The actual size of the string returned // will be 4*sz. func randomUrlsafeStr(sz int) (string, error) { r := make([]byte, 3*sz) _, err := rand.Read(r) if err != nil { return "", fmt.Errorf("error generating random string: %w", err) } return base64.RawURLEncoding.EncodeToString(r), nil }
// SPDX-License-Identifier: AGPL-3.0-only // SPDX-FileCopyrightText: Copyright (c) 2025 Runxi Yu <https://runxiyu.org> package forge import ( "fmt" "net/http" "strings" "github.com/go-git/go-git/v5" "github.com/go-git/go-git/v5/plumbing" "github.com/go-git/go-git/v5/plumbing/filemode" "github.com/go-git/go-git/v5/plumbing/format/diff" "github.com/go-git/go-git/v5/plumbing/object" "go.lindenii.runxiyu.org/forge/internal/misc" "go.lindenii.runxiyu.org/forge/internal/web" ) // usableFilePatch is a [diff.FilePatch] that is structured in a way more // friendly for use in HTML templates. type usableFilePatch struct { From diff.File To diff.File Chunks []usableChunk } // usableChunk is a [diff.Chunk] that is structured in a way more friendly for // use in HTML templates. type usableChunk struct { Operation diff.Operation Content string }
func httpHandleRepoCommit(writer http.ResponseWriter, request *http.Request, params map[string]any) {
func (s *Server) httpHandleRepoCommit(writer http.ResponseWriter, request *http.Request, params map[string]any) {
var repo *git.Repository var commitIDStrSpec, commitIDStrSpecNoSuffix string var commitID plumbing.Hash var parentCommitHash plumbing.Hash var commitObj *object.Commit var commitIDStr string var err error var patch *object.Patch repo, commitIDStrSpec = params["repo"].(*git.Repository), params["commit_id"].(string) commitIDStrSpecNoSuffix = strings.TrimSuffix(commitIDStrSpec, ".patch") commitID = plumbing.NewHash(commitIDStrSpecNoSuffix) if commitObj, err = repo.CommitObject(commitID); err != nil {
web.ErrorPage500(templates, writer, params, "Error getting commit object: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error getting commit object: "+err.Error())
return } if commitIDStrSpecNoSuffix != commitIDStrSpec { var patchStr string if patchStr, err = fmtCommitPatch(commitObj); err != nil {
web.ErrorPage500(templates, writer, params, "Error formatting patch: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error formatting patch: "+err.Error())
return } fmt.Fprintln(writer, patchStr) return } commitIDStr = commitObj.Hash.String() if commitIDStr != commitIDStrSpec { http.Redirect(writer, request, commitIDStr, http.StatusSeeOther) return } params["commit_object"] = commitObj params["commit_id"] = commitIDStr parentCommitHash, patch, err = commitToPatch(commitObj) if err != nil {
web.ErrorPage500(templates, writer, params, "Error getting patch from commit: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error getting patch from commit: "+err.Error())
return } params["parent_commit_hash"] = parentCommitHash.String() params["patch"] = patch params["file_patches"] = makeUsableFilePatches(patch)
renderTemplate(writer, "repo_commit", params)
s.renderTemplate(writer, "repo_commit", params)
} type fakeDiffFile struct { hash plumbing.Hash mode filemode.FileMode path string } func (f fakeDiffFile) Hash() plumbing.Hash { return f.hash } func (f fakeDiffFile) Mode() filemode.FileMode { return f.mode } func (f fakeDiffFile) Path() string { return f.path } var nullFakeDiffFile = fakeDiffFile{ //nolint:gochecknoglobals hash: plumbing.NewHash("0000000000000000000000000000000000000000"), mode: misc.FirstOrPanic(filemode.New("100644")), path: "", } func makeUsableFilePatches(patch diff.Patch) (usableFilePatches []usableFilePatch) { // TODO: Remove unnecessary context // TODO: Prepend "+"/"-"/" " instead of solely distinguishing based on color for _, filePatch := range patch.FilePatches() { var fromFile, toFile diff.File var ufp usableFilePatch chunks := []usableChunk{} fromFile, toFile = filePatch.Files() if fromFile == nil { fromFile = nullFakeDiffFile } if toFile == nil { toFile = nullFakeDiffFile } for _, chunk := range filePatch.Chunks() { var content string content = chunk.Content() if len(content) > 0 && content[0] == '\n' { content = "\n" + content } // Horrible hack to fix how browsers newlines that immediately proceed <pre> chunks = append(chunks, usableChunk{ Operation: chunk.Type(), Content: content, }) } ufp = usableFilePatch{ Chunks: chunks, From: fromFile, To: toFile, } usableFilePatches = append(usableFilePatches, ufp) } return }
// SPDX-License-Identifier: AGPL-3.0-only // SPDX-FileCopyrightText: Copyright (c) 2025 Runxi Yu <https://runxiyu.org> package forge import ( "net/http" "github.com/jackc/pgx/v5" "go.lindenii.runxiyu.org/forge/internal/web" ) // idTitleStatus describes properties of a merge request that needs to be // present in MR listings. type idTitleStatus struct { ID int Title string Status string } // httpHandleRepoContribIndex provides an index to merge requests of a repo. func (s *Server) httpHandleRepoContribIndex(writer http.ResponseWriter, request *http.Request, params map[string]any) { var rows pgx.Rows var result []idTitleStatus var err error if rows, err = s.database.Query(request.Context(), "SELECT repo_local_id, COALESCE(title, 'Untitled'), status FROM merge_requests WHERE repo_id = $1", params["repo_id"], ); err != nil {
web.ErrorPage500(templates, writer, params, "Error querying merge requests: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error querying merge requests: "+err.Error())
return } defer rows.Close() for rows.Next() { var mrID int var mrTitle, mrStatus string if err = rows.Scan(&mrID, &mrTitle, &mrStatus); err != nil {
web.ErrorPage500(templates, writer, params, "Error scanning merge request: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error scanning merge request: "+err.Error())
return } result = append(result, idTitleStatus{mrID, mrTitle, mrStatus}) } if err = rows.Err(); err != nil {
web.ErrorPage500(templates, writer, params, "Error ranging over merge requests: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error ranging over merge requests: "+err.Error())
return } params["merge_requests"] = result
renderTemplate(writer, "repo_contrib_index", params)
s.renderTemplate(writer, "repo_contrib_index", params)
}
// SPDX-License-Identifier: AGPL-3.0-only // SPDX-FileCopyrightText: Copyright (c) 2025 Runxi Yu <https://runxiyu.org> package forge import ( "net/http" "strconv" "github.com/go-git/go-git/v5" "github.com/go-git/go-git/v5/plumbing" "github.com/go-git/go-git/v5/plumbing/object" "go.lindenii.runxiyu.org/forge/internal/web" ) // httpHandleRepoContribOne provides an interface to each merge request of a // repo. func (s *Server) httpHandleRepoContribOne(writer http.ResponseWriter, request *http.Request, params map[string]any) { var mrIDStr string var mrIDInt int var err error var title, status, srcRefStr, dstBranchStr string var repo *git.Repository var srcRefHash plumbing.Hash var dstBranchHash plumbing.Hash var srcCommit, dstCommit, mergeBaseCommit *object.Commit var mergeBases []*object.Commit mrIDStr = params["mr_id"].(string) mrIDInt64, err := strconv.ParseInt(mrIDStr, 10, strconv.IntSize) if err != nil {
web.ErrorPage400(templates, writer, params, "Merge request ID not an integer")
web.ErrorPage400(s.templates, writer, params, "Merge request ID not an integer")
return } mrIDInt = int(mrIDInt64) if err = s.database.QueryRow(request.Context(), "SELECT COALESCE(title, ''), status, source_ref, COALESCE(destination_branch, '') FROM merge_requests WHERE repo_id = $1 AND repo_local_id = $2", params["repo_id"], mrIDInt, ).Scan(&title, &status, &srcRefStr, &dstBranchStr); err != nil {
web.ErrorPage500(templates, writer, params, "Error querying merge request: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error querying merge request: "+err.Error())
return } repo = params["repo"].(*git.Repository) if srcRefHash, err = getRefHash(repo, "branch", srcRefStr); err != nil {
web.ErrorPage500(templates, writer, params, "Error getting source ref hash: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error getting source ref hash: "+err.Error())
return } if srcCommit, err = repo.CommitObject(srcRefHash); err != nil {
web.ErrorPage500(templates, writer, params, "Error getting source commit: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error getting source commit: "+err.Error())
return } params["source_commit"] = srcCommit if dstBranchStr == "" { dstBranchStr = "HEAD" dstBranchHash, err = getRefHash(repo, "", "") } else { dstBranchHash, err = getRefHash(repo, "branch", dstBranchStr) } if err != nil {
web.ErrorPage500(templates, writer, params, "Error getting destination branch hash: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error getting destination branch hash: "+err.Error())
return } if dstCommit, err = repo.CommitObject(dstBranchHash); err != nil {
web.ErrorPage500(templates, writer, params, "Error getting destination commit: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error getting destination commit: "+err.Error())
return } params["destination_commit"] = dstCommit if mergeBases, err = srcCommit.MergeBase(dstCommit); err != nil {
web.ErrorPage500(templates, writer, params, "Error getting merge base: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error getting merge base: "+err.Error())
return } if len(mergeBases) < 1 {
web.ErrorPage500(templates, writer, params, "No merge base found for this merge request; these two branches do not share any common history")
web.ErrorPage500(s.templates, writer, params, "No merge base found for this merge request; these two branches do not share any common history")
// TODO return } mergeBaseCommit = mergeBases[0] params["merge_base"] = mergeBaseCommit patch, err := mergeBaseCommit.Patch(srcCommit) if err != nil {
web.ErrorPage500(templates, writer, params, "Error getting patch: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error getting patch: "+err.Error())
return } params["file_patches"] = makeUsableFilePatches(patch) params["mr_title"], params["mr_status"], params["mr_source_ref"], params["mr_destination_branch"] = title, status, srcRefStr, dstBranchStr
renderTemplate(writer, "repo_contrib_one", params)
s.renderTemplate(writer, "repo_contrib_one", params)
}
// SPDX-License-Identifier: AGPL-3.0-only // SPDX-FileCopyrightText: Copyright (c) 2025 Runxi Yu <https://runxiyu.org> package forge import ( "net/http" "go.lindenii.runxiyu.org/forge/internal/git2c" "go.lindenii.runxiyu.org/forge/internal/render" "go.lindenii.runxiyu.org/forge/internal/web" ) // httpHandleRepoIndex provides the front page of a repo using git2d. func (s *Server) httpHandleRepoIndex(w http.ResponseWriter, req *http.Request, params map[string]any) { repoName := params["repo_name"].(string) groupPath := params["group_path"].([]string) _, repoPath, _, _, _, _, _ := s.getRepoInfo(req.Context(), groupPath, repoName, "") // TODO: Don't use getRepoInfo client, err := git2c.NewClient(s.config.Git.Socket) if err != nil {
web.ErrorPage500(templates, w, params, err.Error())
web.ErrorPage500(s.templates, w, params, err.Error())
return } defer client.Close() commits, readme, err := client.Cmd1(repoPath) if err != nil {
web.ErrorPage500(templates, w, params, err.Error())
web.ErrorPage500(s.templates, w, params, err.Error())
return } params["commits"] = commits params["readme_filename"] = readme.Filename _, params["readme"] = render.Readme(readme.Content, readme.Filename)
renderTemplate(w, "repo_index", params)
s.renderTemplate(w, "repo_index", params)
// TODO: Caching }
// SPDX-License-Identifier: AGPL-3.0-only // SPDX-FileCopyrightText: Copyright (c) 2025 Runxi Yu <https://runxiyu.org> package forge import ( "net/http" "github.com/go-git/go-git/v5" "github.com/go-git/go-git/v5/plumbing" "go.lindenii.runxiyu.org/forge/internal/web" ) // httpHandleRepoLog provides a page with a complete Git log. // // TODO: This currently provides all commits in the branch. It should be // paginated and cached instead.
func httpHandleRepoLog(writer http.ResponseWriter, _ *http.Request, params map[string]any) {
func (s *Server) httpHandleRepoLog(writer http.ResponseWriter, _ *http.Request, params map[string]any) {
var repo *git.Repository var refHash plumbing.Hash var err error repo = params["repo"].(*git.Repository) if refHash, err = getRefHash(repo, params["ref_type"].(string), params["ref_name"].(string)); err != nil {
web.ErrorPage500(templates, writer, params, "Error getting ref hash: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error getting ref hash: "+err.Error())
return } logOptions := git.LogOptions{From: refHash} //exhaustruct:ignore commitIter, err := repo.Log(&logOptions) if err != nil {
web.ErrorPage500(templates, writer, params, "Error getting recent commits: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error getting recent commits: "+err.Error())
return } params["commits"], params["commits_err"] = commitIterSeqErr(commitIter)
renderTemplate(writer, "repo_log", params)
s.renderTemplate(writer, "repo_log", params)
}
// SPDX-License-Identifier: AGPL-3.0-only // SPDX-FileCopyrightText: Copyright (c) 2025 Runxi Yu <https://runxiyu.org> package forge import ( "fmt" "html/template" "net/http" "strings" "go.lindenii.runxiyu.org/forge/internal/git2c" "go.lindenii.runxiyu.org/forge/internal/misc" "go.lindenii.runxiyu.org/forge/internal/web" ) // httpHandleRepoRaw serves raw files, or directory listings that point to raw // files. func (s *Server) httpHandleRepoRaw(writer http.ResponseWriter, request *http.Request, params map[string]any) { repoName := params["repo_name"].(string) groupPath := params["group_path"].([]string) rawPathSpec := params["rest"].(string) pathSpec := strings.TrimSuffix(rawPathSpec, "/") params["path_spec"] = pathSpec _, repoPath, _, _, _, _, _ := s.getRepoInfo(request.Context(), groupPath, repoName, "") client, err := git2c.NewClient(s.config.Git.Socket) if err != nil {
web.ErrorPage500(templates, writer, params, err.Error())
web.ErrorPage500(s.templates, writer, params, err.Error())
return } defer client.Close() files, content, err := client.Cmd2(repoPath, pathSpec) if err != nil {
web.ErrorPage500(templates, writer, params, err.Error())
web.ErrorPage500(s.templates, writer, params, err.Error())
return } switch { case files != nil: params["files"] = files params["readme_filename"] = "README.md" params["readme"] = template.HTML("<p>README rendering here is WIP again</p>") // TODO
renderTemplate(writer, "repo_raw_dir", params)
s.renderTemplate(writer, "repo_raw_dir", params)
case content != "": if misc.RedirectNoDir(writer, request) { return } writer.Header().Set("Content-Type", "application/octet-stream") fmt.Fprint(writer, content) default:
web.ErrorPage500(templates, writer, params, "Unknown error fetching repo raw data")
web.ErrorPage500(s.templates, writer, params, "Unknown error fetching repo raw data")
} }
// SPDX-License-Identifier: AGPL-3.0-only // SPDX-FileCopyrightText: Copyright (c) 2025 Runxi Yu <https://runxiyu.org> package forge import ( "html/template" "net/http" "strings" "go.lindenii.runxiyu.org/forge/internal/git2c" "go.lindenii.runxiyu.org/forge/internal/render" "go.lindenii.runxiyu.org/forge/internal/web" ) // httpHandleRepoTree provides a friendly, syntax-highlighted view of // individual files, and provides directory views that link to these files. // // TODO: Do not highlight files that are too large. func (s *Server) httpHandleRepoTree(writer http.ResponseWriter, request *http.Request, params map[string]any) { repoName := params["repo_name"].(string) groupPath := params["group_path"].([]string) rawPathSpec := params["rest"].(string) pathSpec := strings.TrimSuffix(rawPathSpec, "/") params["path_spec"] = pathSpec _, repoPath, _, _, _, _, _ := s.getRepoInfo(request.Context(), groupPath, repoName, "") client, err := git2c.NewClient(s.config.Git.Socket) if err != nil {
web.ErrorPage500(templates, writer, params, err.Error())
web.ErrorPage500(s.templates, writer, params, err.Error())
return } defer client.Close() files, content, err := client.Cmd2(repoPath, pathSpec) if err != nil {
web.ErrorPage500(templates, writer, params, err.Error())
web.ErrorPage500(s.templates, writer, params, err.Error())
return } switch { case files != nil: params["files"] = files params["readme_filename"] = "README.md" params["readme"] = template.HTML("<p>README rendering here is WIP again</p>") // TODO
renderTemplate(writer, "repo_tree_dir", params)
s.renderTemplate(writer, "repo_tree_dir", params)
case content != "": rendered := render.Highlight(pathSpec, content) params["file_contents"] = rendered
renderTemplate(writer, "repo_tree_file", params)
s.renderTemplate(writer, "repo_tree_file", params)
default:
web.ErrorPage500(templates, writer, params, "Unknown object type, something is seriously wrong")
web.ErrorPage500(s.templates, writer, params, "Unknown object type, something is seriously wrong")
} }
// SPDX-License-Identifier: AGPL-3.0-only // SPDX-FileCopyrightText: Copyright (c) 2025 Runxi Yu <https://runxiyu.org> package forge import ( "net/http" "go.lindenii.runxiyu.org/forge/internal/web" ) // httpHandleUsers is a useless stub.
func httpHandleUsers(writer http.ResponseWriter, _ *http.Request, params map[string]any) { web.ErrorPage501(templates, writer, params)
func (s *Server) httpHandleUsers(writer http.ResponseWriter, _ *http.Request, params map[string]any) { web.ErrorPage501(s.templates, writer, params)
}
// SPDX-License-Identifier: AGPL-3.0-only // SPDX-FileCopyrightText: Copyright (c) 2025 Runxi Yu <https://runxiyu.org> package forge import ( "errors" "log/slog" "net/http" "net/url" "strconv" "strings" "github.com/jackc/pgx/v5" "go.lindenii.runxiyu.org/forge/internal/misc" "go.lindenii.runxiyu.org/forge/internal/web" ) // ServeHTTP handles all incoming HTTP requests and routes them to the correct // location. // // TODO: This function is way too large. func (s *Server) ServeHTTP(writer http.ResponseWriter, request *http.Request) { var remoteAddr string if s.config.HTTP.ReverseProxy { remoteAddrs, ok := request.Header["X-Forwarded-For"] if ok && len(remoteAddrs) == 1 { remoteAddr = remoteAddrs[0] } else { remoteAddr = request.RemoteAddr } } else { remoteAddr = request.RemoteAddr } slog.Info("incoming http", "addr", remoteAddr, "method", request.Method, "uri", request.RequestURI) var segments []string var err error var sepIndex int params := make(map[string]any) if segments, _, err = misc.ParseReqURI(request.RequestURI); err != nil {
web.ErrorPage400(templates, writer, params, "Error parsing request URI: "+err.Error())
web.ErrorPage400(s.templates, writer, params, "Error parsing request URI: "+err.Error())
return } dirMode := false if segments[len(segments)-1] == "" { dirMode = true segments = segments[:len(segments)-1] } params["url_segments"] = segments params["dir_mode"] = dirMode params["global"] = s.globalData var userID int // 0 for none userID, params["username"], err = s.getUserFromRequest(request) params["user_id"] = userID if err != nil && !errors.Is(err, http.ErrNoCookie) && !errors.Is(err, pgx.ErrNoRows) {
web.ErrorPage500(templates, writer, params, "Error getting user info from request: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error getting user info from request: "+err.Error())
return } if userID == 0 { params["user_id_string"] = "" } else { params["user_id_string"] = strconv.Itoa(userID) } for _, v := range segments { if strings.Contains(v, ":") {
web.ErrorPage400Colon(templates, writer, params)
web.ErrorPage400Colon(s.templates, writer, params)
return } } if len(segments) == 0 { s.httpHandleIndex(writer, request, params) return } if segments[0] == "-" { if len(segments) < 2 {
web.ErrorPage404(templates, writer, params)
web.ErrorPage404(s.templates, writer, params)
return } else if len(segments) == 2 && misc.RedirectDir(writer, request) { return } switch segments[1] { case "static": s.staticHandler.ServeHTTP(writer, request) return case "source": s.sourceHandler.ServeHTTP(writer, request) return } } if segments[0] == "-" { switch segments[1] { case "login": s.httpHandleLogin(writer, request, params) return case "users":
httpHandleUsers(writer, request, params)
s.httpHandleUsers(writer, request, params)
return default:
web.ErrorPage404(templates, writer, params)
web.ErrorPage404(s.templates, writer, params)
return } } sepIndex = -1 for i, part := range segments { if part == "-" { sepIndex = i break } } params["separator_index"] = sepIndex var groupPath []string var moduleType string var moduleName string if sepIndex > 0 { groupPath = segments[:sepIndex] } else { groupPath = segments } params["group_path"] = groupPath switch { case sepIndex == -1: if misc.RedirectDir(writer, request) { return } s.httpHandleGroupIndex(writer, request, params) case len(segments) == sepIndex+1:
web.ErrorPage404(templates, writer, params)
web.ErrorPage404(s.templates, writer, params)
return case len(segments) == sepIndex+2:
web.ErrorPage404(templates, writer, params)
web.ErrorPage404(s.templates, writer, params)
return default: moduleType = segments[sepIndex+1] moduleName = segments[sepIndex+2] switch moduleType { case "repos": params["repo_name"] = moduleName if len(segments) > sepIndex+3 { switch segments[sepIndex+3] { case "info": if err = s.httpHandleRepoInfo(writer, request, params); err != nil {
web.ErrorPage500(templates, writer, params, err.Error())
web.ErrorPage500(s.templates, writer, params, err.Error())
} return case "git-upload-pack": if err = s.httpHandleUploadPack(writer, request, params); err != nil {
web.ErrorPage500(templates, writer, params, err.Error())
web.ErrorPage500(s.templates, writer, params, err.Error())
} return } } if params["ref_type"], params["ref_name"], err = misc.GetParamRefTypeName(request); err != nil { if errors.Is(err, misc.ErrNoRefSpec) { params["ref_type"] = "" } else {
web.ErrorPage400(templates, writer, params, "Error querying ref type: "+err.Error())
web.ErrorPage400(s.templates, writer, params, "Error querying ref type: "+err.Error())
return } } if params["repo"], params["repo_description"], params["repo_id"], _, err = s.openRepo(request.Context(), groupPath, moduleName); err != nil {
web.ErrorPage500(templates, writer, params, "Error opening repo: "+err.Error())
web.ErrorPage500(s.templates, writer, params, "Error opening repo: "+err.Error())
return } repoURLRoot := "/" for _, part := range segments[:sepIndex+3] { repoURLRoot = repoURLRoot + url.PathEscape(part) + "/" } params["repo_url_root"] = repoURLRoot params["repo_patch_mailing_list"] = repoURLRoot[1:len(repoURLRoot)-1] + "@" + s.config.LMTP.Domain params["http_clone_url"] = s.genHTTPRemoteURL(groupPath, moduleName) params["ssh_clone_url"] = s.genSSHRemoteURL(groupPath, moduleName) if len(segments) == sepIndex+3 { if misc.RedirectDir(writer, request) { return } s.httpHandleRepoIndex(writer, request, params) return } repoFeature := segments[sepIndex+3] switch repoFeature { case "tree": if misc.AnyContain(segments[sepIndex+4:], "/") {
web.ErrorPage400(templates, writer, params, "Repo tree paths may not contain slashes in any segments")
web.ErrorPage400(s.templates, writer, params, "Repo tree paths may not contain slashes in any segments")
return } if dirMode { params["rest"] = strings.Join(segments[sepIndex+4:], "/") + "/" } else { params["rest"] = strings.Join(segments[sepIndex+4:], "/") } if len(segments) < sepIndex+5 && misc.RedirectDir(writer, request) { return } s.httpHandleRepoTree(writer, request, params) case "branches": if misc.RedirectDir(writer, request) { return } s.httpHandleRepoBranches(writer, request, params) return case "raw": if misc.AnyContain(segments[sepIndex+4:], "/") {
web.ErrorPage400(templates, writer, params, "Repo tree paths may not contain slashes in any segments")
web.ErrorPage400(s.templates, writer, params, "Repo tree paths may not contain slashes in any segments")
return } if dirMode { params["rest"] = strings.Join(segments[sepIndex+4:], "/") + "/" } else { params["rest"] = strings.Join(segments[sepIndex+4:], "/") } if len(segments) < sepIndex+5 && misc.RedirectDir(writer, request) { return } s.httpHandleRepoRaw(writer, request, params) case "log": if len(segments) > sepIndex+4 {
web.ErrorPage400(templates, writer, params, "Too many parameters")
web.ErrorPage400(s.templates, writer, params, "Too many parameters")
return } if misc.RedirectDir(writer, request) { return }
httpHandleRepoLog(writer, request, params)
s.httpHandleRepoLog(writer, request, params)
case "commit": if len(segments) != sepIndex+5 {
web.ErrorPage400(templates, writer, params, "Incorrect number of parameters")
web.ErrorPage400(s.templates, writer, params, "Incorrect number of parameters")
return } if misc.RedirectNoDir(writer, request) { return } params["commit_id"] = segments[sepIndex+4]
httpHandleRepoCommit(writer, request, params)
s.httpHandleRepoCommit(writer, request, params)
case "contrib": if misc.RedirectDir(writer, request) { return } switch len(segments) { case sepIndex + 4: s.httpHandleRepoContribIndex(writer, request, params) case sepIndex + 5: params["mr_id"] = segments[sepIndex+4] s.httpHandleRepoContribOne(writer, request, params) default:
web.ErrorPage400(templates, writer, params, "Too many parameters")
web.ErrorPage400(s.templates, writer, params, "Too many parameters")
} default:
web.ErrorPage404(templates, writer, params)
web.ErrorPage404(s.templates, writer, params)
return } default:
web.ErrorPage404(templates, writer, params)
web.ErrorPage404(s.templates, writer, params)
return } } }
// SPDX-License-Identifier: AGPL-3.0-only // SPDX-FileCopyrightText: Copyright (c) 2025 Runxi Yu <https://runxiyu.org> package forge import ( "log/slog" "net/http" ) // renderTemplate abstracts out the annoyances of reporting template rendering // errors.
func renderTemplate(w http.ResponseWriter, templateName string, params map[string]any) { if err := templates.ExecuteTemplate(w, templateName, params); err != nil {
func (s *Server) renderTemplate(w http.ResponseWriter, templateName string, params map[string]any) { if err := s.templates.ExecuteTemplate(w, templateName, params); err != nil {
http.Error(w, "error rendering template: "+err.Error(), http.StatusInternalServerError) slog.Error("error rendering template", "error", err.Error()) } }
// SPDX-License-Identifier: AGPL-3.0-only // SPDX-FileCopyrightText: Copyright (c) 2025 Runxi Yu <https://runxiyu.org> package forge import ( "embed" "html/template" "io/fs" "github.com/tdewolff/minify/v2" "github.com/tdewolff/minify/v2/html" "go.lindenii.runxiyu.org/forge/internal/misc" ) //go:embed LICENSE source.tar.gz var embeddedSourceFS embed.FS //go:embed templates/* static/* //go:embed hookc/hookc git2d/git2d var embeddedResourcesFS embed.FS
var templates *template.Template //nolint:gochecknoglobals
// loadTemplates minifies and loads HTML templates.
func loadTemplates() (err error) {
func (s *Server) loadTemplates() (err error) {
minifier := minify.New() minifierOptions := html.Minifier{ TemplateDelims: [2]string{"{{", "}}"}, KeepDefaultAttrVals: true, } //exhaustruct:ignore minifier.Add("text/html", &minifierOptions)
templates = template.New("templates").Funcs(template.FuncMap{
s.templates = template.New("templates").Funcs(template.FuncMap{
"first_line": misc.FirstLine, "path_escape": misc.PathEscape, "query_escape": misc.QueryEscape, "dereference_error": misc.DereferenceOrZero[error], "minus": misc.Minus, }) err = fs.WalkDir(embeddedResourcesFS, "templates", func(path string, d fs.DirEntry, err error) error { if err != nil { return err } if !d.IsDir() { content, err := fs.ReadFile(embeddedResourcesFS, path) if err != nil { return err } minified, err := minifier.Bytes("text/html", content) if err != nil { return err }
_, err = templates.Parse(misc.BytesToString(minified))
_, err = s.templates.Parse(misc.BytesToString(minified))
if err != nil { return err } } return nil }) return err }
// SPDX-License-Identifier: AGPL-3.0-only // SPDX-FileCopyrightText: Copyright (c) 2025 Runxi Yu <https://runxiyu.org> package forge import ( "errors"
"html/template"
"io/fs" "log" "log/slog" "net" "net/http" "os" "os/exec" "syscall" "time" "go.lindenii.runxiyu.org/forge/internal/database" "go.lindenii.runxiyu.org/lindenii-common/cmap" goSSH "golang.org/x/crypto/ssh" ) type Server struct { config Config database database.Database sourceHandler http.Handler staticHandler http.Handler ircSendBuffered chan string ircSendDirectChan chan errorBack[string] // globalData is passed as "global" when rendering HTML templates. globalData map[string]any serverPubkeyString string serverPubkeyFP string serverPubkey goSSH.PublicKey // packPasses contains hook cookies mapped to their packPass. packPasses cmap.Map[string, packPass]
templates *template.Template
} func (s *Server) Setup() { s.sourceHandler = http.StripPrefix( "/-/source/", http.FileServer(http.FS(embeddedSourceFS)), ) staticFS, err := fs.Sub(embeddedResourcesFS, "static") if err != nil { panic(err) } s.staticHandler = http.StripPrefix("/-/static/", http.FileServer(http.FS(staticFS))) s.globalData = map[string]any{ "server_public_key_string": &s.serverPubkeyString, "server_public_key_fingerprint": &s.serverPubkeyFP, "forge_version": version, // Some other ones are populated after config parsing } } func (s *Server) Run() { if err := s.deployHooks(); err != nil { slog.Error("deploying hooks", "error", err) os.Exit(1) }
if err := loadTemplates(); err != nil {
if err := s.loadTemplates(); err != nil {
slog.Error("loading templates", "error", err) os.Exit(1) } if err := s.deployGit2D(); err != nil { slog.Error("deploying git2d", "error", err) os.Exit(1) } // Launch Git2D go func() { cmd := exec.Command(s.config.Git.DaemonPath, s.config.Git.Socket) //#nosec G204 cmd.Stderr = log.Writer() cmd.Stdout = log.Writer() if err := cmd.Run(); err != nil { panic(err) } }() // UNIX socket listener for hooks { hooksListener, err := net.Listen("unix", s.config.Hooks.Socket) if errors.Is(err, syscall.EADDRINUSE) { slog.Warn("removing existing socket", "path", s.config.Hooks.Socket) if err = syscall.Unlink(s.config.Hooks.Socket); err != nil { slog.Error("removing existing socket", "path", s.config.Hooks.Socket, "error", err) os.Exit(1) } if hooksListener, err = net.Listen("unix", s.config.Hooks.Socket); err != nil { slog.Error("listening hooks", "error", err) os.Exit(1) } } else if err != nil { slog.Error("listening hooks", "error", err) os.Exit(1) } slog.Info("listening hooks on unix", "path", s.config.Hooks.Socket) go func() { if err = s.serveGitHooks(hooksListener); err != nil { slog.Error("serving hooks", "error", err) os.Exit(1) } }() } // UNIX socket listener for LMTP { lmtpListener, err := net.Listen("unix", s.config.LMTP.Socket) if errors.Is(err, syscall.EADDRINUSE) { slog.Warn("removing existing socket", "path", s.config.LMTP.Socket) if err = syscall.Unlink(s.config.LMTP.Socket); err != nil { slog.Error("removing existing socket", "path", s.config.LMTP.Socket, "error", err) os.Exit(1) } if lmtpListener, err = net.Listen("unix", s.config.LMTP.Socket); err != nil { slog.Error("listening LMTP", "error", err) os.Exit(1) } } else if err != nil { slog.Error("listening LMTP", "error", err) os.Exit(1) } slog.Info("listening LMTP on unix", "path", s.config.LMTP.Socket) go func() { if err = s.serveLMTP(lmtpListener); err != nil { slog.Error("serving LMTP", "error", err) os.Exit(1) } }() } // SSH listener { sshListener, err := net.Listen(s.config.SSH.Net, s.config.SSH.Addr) if errors.Is(err, syscall.EADDRINUSE) && s.config.SSH.Net == "unix" { slog.Warn("removing existing socket", "path", s.config.SSH.Addr) if err = syscall.Unlink(s.config.SSH.Addr); err != nil { slog.Error("removing existing socket", "path", s.config.SSH.Addr, "error", err) os.Exit(1) } if sshListener, err = net.Listen(s.config.SSH.Net, s.config.SSH.Addr); err != nil { slog.Error("listening SSH", "error", err) os.Exit(1) } } else if err != nil { slog.Error("listening SSH", "error", err) os.Exit(1) } slog.Info("listening SSH on", "net", s.config.SSH.Net, "addr", s.config.SSH.Addr) go func() { if err = s.serveSSH(sshListener); err != nil { slog.Error("serving SSH", "error", err) os.Exit(1) } }() } // HTTP listener { httpListener, err := net.Listen(s.config.HTTP.Net, s.config.HTTP.Addr) if errors.Is(err, syscall.EADDRINUSE) && s.config.HTTP.Net == "unix" { slog.Warn("removing existing socket", "path", s.config.HTTP.Addr) if err = syscall.Unlink(s.config.HTTP.Addr); err != nil { slog.Error("removing existing socket", "path", s.config.HTTP.Addr, "error", err) os.Exit(1) } if httpListener, err = net.Listen(s.config.HTTP.Net, s.config.HTTP.Addr); err != nil { slog.Error("listening HTTP", "error", err) os.Exit(1) } } else if err != nil { slog.Error("listening HTTP", "error", err) os.Exit(1) } server := http.Server{ Handler: s, ReadTimeout: time.Duration(s.config.HTTP.ReadTimeout) * time.Second, WriteTimeout: time.Duration(s.config.HTTP.ReadTimeout) * time.Second, IdleTimeout: time.Duration(s.config.HTTP.ReadTimeout) * time.Second, } //exhaustruct:ignore slog.Info("listening HTTP on", "net", s.config.HTTP.Net, "addr", s.config.HTTP.Addr) go func() { if err = server.Serve(httpListener); err != nil && !errors.Is(err, http.ErrServerClosed) { slog.Error("serving HTTP", "error", err) os.Exit(1) } }() } // IRC bot go s.ircBotLoop() select {} }