summaryrefslogtreecommitdiffhomepage
path: root/ipn/ipnlocal/peerapi_sync.go
blob: b7c6a2d46d5febb8fb4e33cbd6900b59a702a87d (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
// Copyright (c) Tailscale Inc & contributors
// SPDX-License-Identifier: BSD-3-Clause

//go:build !ts_omit_sync

package ipnlocal

import (
	"net/http"
	"strings"

	"tailscale.com/tailcfg"
	"tailscale.com/tailsync"
)

const tailsyncPrefix = "/v0/sync"

func init() {
	peerAPIHandlerPrefixes[tailsyncPrefix] = handleServeSync
}

func handleServeSync(hi PeerAPIHandler, w http.ResponseWriter, r *http.Request) {
	h := hi.(*peerAPIHandler)

	h.logfv1("tailsync: got %s request from %s", r.Method, h.peerNode.Key().ShortString())
	if !h.ps.b.SyncSharingEnabled() {
		h.logf("tailsync: not enabled")
		http.Error(w, "tailsync not enabled", http.StatusNotFound)
		return
	}

	capsMap := h.PeerCaps()
	syncCaps, ok := capsMap[tailcfg.PeerCapabilityTailsync]
	if !ok {
		h.logf("tailsync: not permitted")
		http.Error(w, "tailsync not permitted", http.StatusForbidden)
		return
	}

	rawPerms := make([][]byte, 0, len(syncCaps))
	for _, cap := range syncCaps {
		rawPerms = append(rawPerms, []byte(cap))
	}

	p, err := tailsync.ParsePermissions(rawPerms)
	if err != nil {
		h.logf("tailsync: error parsing permissions: %v", err)
		http.Error(w, err.Error(), http.StatusInternalServerError)
		return
	}

	fs, ok := h.ps.b.sys.FileSync.GetOK()
	if !ok {
		h.logf("tailsync: not supported on platform")
		http.Error(w, "tailsync not supported on platform", http.StatusNotFound)
		return
	}

	r.URL.Path = strings.TrimPrefix(r.URL.Path, tailsyncPrefix)
	fs.ServeHTTPWithPerms(p, w, r)
}